Junglewise Threat Intelligence

CVE-2026-27880: Grafana denial of service in OpenFeature evaluation endpoint

CVE-2026-27880 · Severity: high · CVSS 7.5 · Published 2026-03-27

Technologies: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9. Vendors: Grafana Labs, Red Hat.

Executive brief

Grafana, a popular data visualization and monitoring platform, is vulnerable to a denial-of-service attack. An attacker can send specially crafted requests to the feature toggle evaluation endpoint, causing the system to consume excessive memory and crash. This can lead to service outages, preventing teams from monitoring their infrastructure and applications.

Technical details

A denial-of-service vulnerability exists in Grafana's implementation of the OpenFeature evaluation API. The endpoint responsible for feature toggle evaluation fails to properly bound or throttle the size of input data read into memory (CWE-770). A remote, unauthenticated attacker can exploit this by sending large or malicious payloads, leading to an out-of-memory (OOM) condition and process crash. The vulnerability affects Grafana versions 12.1.x, 12.2.x, 12.3.x, and 12.4.x. Patches have been released in versions 12.1.10, 12.2.8, 12.3.6, and 12.4.2.

Affected products

  • Grafana Labs Grafana >=12.1.0, <12.1.10; >=12.2.0, <12.2.8; >=12.3.0, <12.3.6; >=12.4.0, <12.4.2
  • Red Hat Red Hat Enterprise Linux 9 affected
  • Red Hat Red Hat Enterprise Linux 10 affected

Timeline

  • 2026-03-27: disclosed
  • 2026-03-30: advisory
  • 2026-03-30: patched

References