Vulnerability Bulletins

CVE-2026-28383

   
Affected software GRAFANA
 
A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-28383