High severity7.5OSV Advisory· Published Jul 10, 2026· Updated Jul 13, 2026
CVE-2026-33382
CVE-2026-33382
Description
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
Affected products
8- osv-coords5 versionspkg:bitnami/grafanapkg:rpm/almalinux/grafanapkg:rpm/almalinux/grafana-selinuxpkg:rpm/opensuse/grafana&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/grafana&distro=openSUSE%20Tumbleweed
>= 11.6.0, < 11.6.15+ 4 more
- (no CPE)range: >= 11.6.0, < 11.6.15
- (no CPE)range: < 10.2.6-28.el10_2.4
- (no CPE)range: < 10.2.6-28.el10_2.4
- (no CPE)range: < 12.4.5-bp160.2.1
- (no CPE)range: < 12.4.5-1.1
Patches
Vulnerability mechanics
References
1- grafana.com/security/security-advisories/cve-2026-33382nvdVendor Advisory
News mentions
1- Grafana: Three Moderate Vulnerabilities Including Stored XSS and DoS Disclosed TogetherVypr Intelligence · Jul 10, 2026