CVE-2026-21723: Grafana OSS

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.

Affected products

  • Grafana Grafana OSS: from 8.0.0, up to and including 11.0.0; from 11.0.0, up to and including 11.6.10; from 12.0.0, up to and including 12.0.9; from 12.1.0, up to and including 12.1.6; from 12.2.0, up to and including 12.2.4; from 12.3.0, up to and including 12.3.2

Published 2026-07-23. Last modified 2026-07-23.