Security Advisory

CVE-2026-28383

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-13 19:28:36
Last updated 2026-07-24 12:23:14
Assigner GRAFANA
CVSS score 6.5
State PUBLISHED

Description

A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service.