{
  "threat_severity" : "Moderate",
  "public_date" : "2026-07-10T14:58:33Z",
  "bugzilla" : {
    "description" : "grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route",
    "id" : "2499061",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2499061"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-770",
  "details" : [ "An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).", "A flaw was found in Grafana. An unauthenticated attacker can repeatedly access the OAuth login route with unique values. This can lead to unbounded memory growth, eventually exhausting system memory and causing the Grafana instance to crash. This results in a denial of service for legitimate users." ],
  "statement" : "The flaw in Grafana is rated Moderate, as an unauthenticated attacker can trigger a denial of service by repeatedly accessing the OAuth login route, leading to unbounded memory growth and instance crashes.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-08-12T00:00:00Z",
    "advisory" : "RHSA-2026:54178",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "grafana-0:10.2.6-28.el10_2.4"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63164",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "grafana13-2-main-13.2.1-0.1.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63165",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "grafana13-1-main-13.1.3-0.5.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-09-08T00:00:00Z",
    "advisory" : "RHSA-2026:65157",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "grafana12-4-main-12.4.10-0.1.hum1"
  } ],
  "package_state" : [ {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Not affected",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-grafana-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Not affected",
    "package_name" : "rhacm2/acm-grafana-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Ceph Storage 5",
    "fix_state" : "Not affected",
    "package_name" : "rhceph/rhceph-5-dashboard-rhel8",
    "cpe" : "cpe:/a:redhat:ceph_storage:5"
  }, {
    "product_name" : "Red Hat Ceph Storage 6",
    "fix_state" : "Not affected",
    "package_name" : "rhceph/rhceph-6-dashboard-rhel9",
    "cpe" : "cpe:/a:redhat:ceph_storage:6"
  }, {
    "product_name" : "Red Hat Ceph Storage 7",
    "fix_state" : "Not affected",
    "package_name" : "rhceph/grafana-rhel9",
    "cpe" : "cpe:/a:redhat:ceph_storage:7"
  }, {
    "product_name" : "Red Hat Ceph Storage 8",
    "fix_state" : "Not affected",
    "package_name" : "rhceph/grafana-rhel9",
    "cpe" : "cpe:/a:redhat:ceph_storage:8"
  }, {
    "product_name" : "Red Hat Ceph Storage 9",
    "fix_state" : "Fix deferred",
    "package_name" : "rhceph/grafana-rhel10",
    "cpe" : "cpe:/a:redhat:ceph_storage:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "grafana",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "grafana",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "fix_state" : "Not affected",
    "package_name" : "hi/grafana",
    "cpe" : "cpe:/a:redhat:hummingbird:1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-8609\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8609\nhttps://grafana.com/security/security-advisories/cve-2026-8609" ],
  "name" : "CVE-2026-8609",
  "mitigation" : {
    "value" : "To mitigate this issue, restrict network access to the Grafana instance to trusted internal networks or localhost. If a reverse proxy or load balancer is deployed in front of Grafana, configure it to implement rate limiting on requests to the OAuth login endpoint to prevent an attacker from exhausting system resources. If OAuth is not required, consider disabling it in the Grafana configuration, though this may impact user authentication workflows.",
    "lang" : "en:us"
  },
  "csaw" : false
}