CVE-2026-8609EPSS p39.3%

CVE-2026-8609CVE-2026-8609

grafana / grafana

Description

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

Scoring

CVSS 5.3 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS0.48% probability of exploitation · percentile 39.3% · 2026-10-05T12:00:23Z
Last modified2026-07-13
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.