BIT-grafana-2026-33375

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-33375.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-grafana-2026-33375
Aliases
  • CVE-2026-33375
Published
2026-04-01T08:41:17.463Z
Modified
2026-04-01T09:16:22.611754Z
Summary
Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS
Details

The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*"
    ]
}
References

Affected packages

Bitnami / grafana

Package

Name
grafana
Purl
pkg:bitnami/grafana

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
11.6.0
Fixed
11.6.14
Introduced
12.1.0
Fixed
12.1.10
Introduced
12.2.0
Fixed
12.2.8
Introduced
12.3.0
Fixed
12.3.6
Introduced
12.4.0
Fixed
12.4.2

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-33375.json"