AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-33382

HIGH · CVSS 7.5 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Several Grafana API endpoints are vulnerable due to a lack of request body size limitations, allowing attackers to send excessively large payloads. This can lead to excessive memory allocation, resulting in denial of service conditions. Organizations using Grafana, particularly those exposing API endpoints, should prioritize addressing this vulnerability to mitigate potential service disruptions.

CVE
CVE-2026-33382
Severity
HIGH
CVSS
7.5
EPSS
0.39%

Original NVD Description

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)