CVE-2026-33382: Grafana

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

Affected products

  • Grafana Grafana: from 11.6.0, before 11.6.15 (fixed in 11.6.15); from 12.2.0, before 12.2.9 (fixed in 12.2.9); from 12.3.0, before 12.3.7 (fixed in 12.3.7); from 12.4.0, before 12.4.4 (fixed in 12.4.4); from 13.0.0, before 13.0.2 (fixed in 13.0.2)

Published 2026-07-10. Last modified 2026-07-13.