AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-8609

MEDIUM · CVSS 5.3 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Grafana's OAuth login route is vulnerable to unauthenticated attacks that exploit unique value submissions, leading to unbounded memory growth and potential denial of service as the application exhausts available memory. Organizations using Grafana should prioritize addressing this vulnerability to prevent service disruptions. This is particularly critical for environments where uptime and availability are essential.

CVE
CVE-2026-8609
Severity
MEDIUM
CVSS
5.3
EPSS
0.40%

Original NVD Description

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

Related CVEs

Other vulnerabilities affecting the same vendor(s)