← Back

CVE-2026-33378

nvd nist
Published: May 13, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: security@grafana.com (Secondary)

Description

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

Affected (13)

Products: Grafana: Grafana
1 product
Grafana
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Grafana
From 12.0.0 to 12.2.8
From 12.3.0 to 12.3.6
From 12.4.0 to 12.4.3
From 8.0.0 to 11.6.14
Version 11.6.14
Version 11.6.14 security01
Version 12.2.8
Version 12.2.8 security01
Version 12.3.6
Version 12.3.6 security01
Version 12.4.3
Version 13.0.0
Version 13.0.1

References (1)

Source: security@grafana.com
Vendor Advisory

Timeline

No history available yet.