CVE-2026-8609: CWE-400 in Grafana Grafana OSS
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
AI Analysis
Technical Summary
This vulnerability (CWE-400) in Grafana OSS allows unauthenticated attackers to cause unbounded memory growth by repeatedly calling the OAuth login route with unique values. The excessive memory consumption can exhaust system resources and crash the Grafana instance, causing denial of service. The CVSS score is 5.3 (medium severity), reflecting network attack vector, low complexity, no privileges or user interaction required, and impact limited to availability. No vendor advisory or patch information is currently available to confirm remediation status.
Potential Impact
An attacker can cause a denial of service by exhausting memory resources on the Grafana OSS server through repeated unauthenticated requests to the OAuth login route. This disrupts service availability but does not affect confidentiality or integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider implementing network-level protections such as rate limiting or filtering requests to the OAuth login endpoint to reduce the risk of exploitation.
CVE-2026-8609: CWE-400 in Grafana Grafana OSS
Description
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
CVSS v3.1
Score 5.3medium
Affected software
pkg:github/grafana/grafanaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-400) in Grafana OSS allows unauthenticated attackers to cause unbounded memory growth by repeatedly calling the OAuth login route with unique values. The excessive memory consumption can exhaust system resources and crash the Grafana instance, causing denial of service. The CVSS score is 5.3 (medium severity), reflecting network attack vector, low complexity, no privileges or user interaction required, and impact limited to availability. No vendor advisory or patch information is currently available to confirm remediation status.
Potential Impact
An attacker can cause a denial of service by exhausting memory resources on the Grafana OSS server through repeated unauthenticated requests to the OAuth login route. This disrupts service availability but does not affect confidentiality or integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider implementing network-level protections such as rate limiting or filtering requests to the OAuth login endpoint to reduce the risk of exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GRAFANA
- Date Reserved
- 2026-05-14T16:01:42.297Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a51144a68715ace43c8e33e
Added to database: 07/10/2026, 15:48:26 UTC
Last enriched: 08/11/2026, 13:41:35 UTC
Last updated: 08/24/2026, 14:08:11 UTC
Views: 105
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.