BIT-grafana-2026-33378

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-33378.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-grafana-2026-33378
Aliases
  • CVE-2026-33378
Published
2026-05-15T08:42:47.427Z
Modified
2026-05-15T11:00:11.318344Z
Summary
Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro
Details

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

Database specific
{
    "cpes": [
        "cpe:2.3:a:grafana:grafana:*:*:*:*:*:go:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / grafana

Package

Name
grafana
Purl
pkg:bitnami/grafana

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
11.6.14
Introduced
12.0.0
Fixed
12.2.8
Introduced
12.3.0
Fixed
12.3.6
Introduced
12.4.0
Fixed
12.4.3
Introduced
13.0.0
Fixed
13.0.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-33378.json"