CVE-2026-33382
Last modified
CVE-2026-33382 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Grafana | Grafana | >= 11.6.0, < 11.6.15 |
| Grafana | Grafana | >= 12.2.0, < 12.2.9 |
| Grafana | Grafana | >= 12.3.0, < 12.3.7 |
| Grafana | Grafana | >= 12.4.0, < 12.4.4 |
| Grafana | Grafana | >= 13.0.0, < 13.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33382?
How severe is CVE-2026-33382?
How do I fix CVE-2026-33382?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33376When using an IPv6 allow-list for the Auth Proxy feature, it…7.4
- CVE-2026-33377An Editor can overwrite a dashboard not owned by them to acq…7.1
- CVE-2026-33378Using the $__timeGroup macro, one can achieve an OOM by over…6.5
- CVE-2026-3338Improper signature validation in PKCS7_verify() in AWS-LC al…8.7
- CVE-2026-33380A vulnerability in SQL Expressions allows an authenticated a…6.5
- CVE-2026-33381When a user's access to mint tokens for a service account is…8.1
- CVE-2026-33384QuickCMS allows a user's session identifier to be set before…4.8
- CVE-2026-33385A Blind SQL injection vulnerability has been identified in Q…5.1
- CVE-2026-33386QuickCMS is vulnerable to Cross-Site Scripting (XSS) through…2.3
- CVE-2026-3339The Keep Backup Daily plugin for WordPress is vulnerable to …2.7
- CVE-2026-33390An Incorrect Privilege Assignment vulnerability was discover…8.1
- CVE-2026-33392In JetBrains YouTrack before 2025.3.131383 high privileged u…7.2
Are you affected by CVE-2026-33382?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
