GHSA-3w66-95m3-8jxg

Suggest an improvement
Source
https://github.com/advisories/GHSA-3w66-95m3-8jxg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-3w66-95m3-8jxg/GHSA-3w66-95m3-8jxg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3w66-95m3-8jxg
Aliases
Downstream
CGA (60)
MINI (18)
Published
2026-06-22T18:34:17Z
Modified
2026-09-21T23:25:40Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Grafana: Pre-authentication denial of service in the public dashboard query handler
Details

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

Database specific
{
    "cwe_ids":  [
        "CWE-400",
        "CWE-770"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-21T23:00:48Z",
    "nvd_published_at":  "2026-06-22T18:16:37Z",
    "severity":  "HIGH"
}
References

Affected packages

Go
github.com/grafana/grafana

Package

Name
github.com/grafana/grafana
View open source insights on deps.dev
Purl
pkg:golang/github.com/grafana/grafana

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0-beta1

Database specific

last_known_affected_version_range
"< 11.6.15"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-3w66-95m3-8jxg/GHSA-3w66-95m3-8jxg.json"
github.com/grafana/grafana

Package

Name
github.com/grafana/grafana
View open source insights on deps.dev
Purl
pkg:golang/github.com/grafana/grafana

Affected ranges

Type
SEMVER
Events
Introduced
12.0.0

Database specific

last_known_affected_version_range
"< 12.2.9"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-3w66-95m3-8jxg/GHSA-3w66-95m3-8jxg.json"
github.com/grafana/grafana

Package

Name
github.com/grafana/grafana
View open source insights on deps.dev
Purl
pkg:golang/github.com/grafana/grafana

Affected ranges

Type
SEMVER
Events
Introduced
12.3.0

Database specific

last_known_affected_version_range
"< 12.3.7"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-3w66-95m3-8jxg/GHSA-3w66-95m3-8jxg.json"
github.com/grafana/grafana

Package

Name
github.com/grafana/grafana
View open source insights on deps.dev
Purl
pkg:golang/github.com/grafana/grafana

Affected ranges

Type
SEMVER
Events
Introduced
12.4.0

Database specific

last_known_affected_version_range
"< 12.4.4"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-3w66-95m3-8jxg/GHSA-3w66-95m3-8jxg.json"
github.com/grafana/grafana

Package

Name
github.com/grafana/grafana
View open source insights on deps.dev
Purl
pkg:golang/github.com/grafana/grafana

Affected ranges

Type
SEMVER
Events
Introduced
13.0.0

Database specific

last_known_affected_version_range
"< 13.0.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-3w66-95m3-8jxg/GHSA-3w66-95m3-8jxg.json"
github.com/grafana/grafana

Package

Name
github.com/grafana/grafana
View open source insights on deps.dev
Purl
pkg:golang/github.com/grafana/grafana

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.9.2-0.20260616075434-82ef13993059

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-3w66-95m3-8jxg/GHSA-3w66-95m3-8jxg.json"