CVE-2026-28375: Grafana
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
Affected products
- Grafana Grafana: before 8.1.0 (fixed in 8.1.0); from 11.6.14, before 12.0.0 (fixed in 12.0.0); from 12.1.10, before 12.2.0 (fixed in 12.2.0); from 12.2.8, before 12.3.0 (fixed in 12.3.0); from 12.3.6, before 12.4.0 (fixed in 12.4.0)
Published 2026-03-27. Last modified 2026-06-17.