CVE-2026-33382
Denial of service via unbounded request body size
7.5
HIGH
CVSS 3.1
EPSS 0.38%
Description
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
How to fix CVE-2026-33382
To remediate CVE-2026-33382, upgrade the affected package to a fixed version below.
- —upgrade to 11.6.15 or later
Is CVE-2026-33382 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 11.6.0, < 11.6.15, >= 12.2.0, < 12.2.9, >= 12.3.0, < 12.3.7, >= 12.4.0, < 12.4.4, >= 13.0.0, < 13.0.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |