Description
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
Remediation
References
Related Vulnerabilities
Lighttpd Uncontrolled Resource Consumption Vulnerability (CVE-2022-30780)
Liferay DXP Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2025-43782)
WordPress Plugin WP Font Awesome Cross-Site Scripting (1.7.8)
WordPress Plugin SpamTask Arbitrary File Upload (1.3.6)
WordPress Plugin WP Customize Login Cross-Site Scripting (1.1)