CVE Field Guide
About Us
CVE-2026-28375
PUBLISHED
Grafana Testdata datasource can issue unbounded memory allocations
Assigner:
GRAFANA
Reserved:
27.02.2026
Published:
27.03.2026
Updated:
27.03.2026
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
Metrics
CVSS 3.1
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS Score:
6.5
CVSS score
6.5
Attack Vector
Network
Scope
Unchanged
Attack Complexity
Low
Confidentiality Impact
None
Privileges Required
Low
Integrity Impact
None
User Interaction
None
Availability Impact
High
CVSS 3.1
Product Status
Vendor
Grafana
Product
Grafana
Versions
Default:
unaffected
affected from v8.1.0 to v11.6.14 (excl.)
affected from v12.0.0 to v12.1.10 (excl.)
affected from v12.2.0 to v12.2.8 (excl.)
affected from v12.3.0 to v12.3.6 (excl.)
affected from v12.4.0 to v12.4.2 (excl.)
References
https://grafana.com/security/security-advisories/cve-2026-28375