Security Advisory

CVE-2026-28376

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-13 19:28:26
Last updated 2026-07-24 12:23:10
Assigner GRAFANA
CVSS score 6.5
State PUBLISHED

Description

The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.