CVE-2026-8609
Pre-authentication denial of service via the OAuth login route
7.5
HIGH
CVSS 3.1
EPSS 0.40%
Description
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
How to fix CVE-2026-8609
To remediate CVE-2026-8609, upgrade the affected package to a fixed version below.
- Bitnami/grafana—upgrade to 11.6.15 or later
Is CVE-2026-8609 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 11.6.0, < 11.6.15, >= 12.2.0, < 12.2.9, >= 12.3.0, < 12.3.7, >= 12.4.0, < 12.4.4, >= 13.0.0, < 13.0.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |