CVE-2026-28376
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
May 13, 2026
Vendor
unknown
Description
The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.