FlawAtlas
Search the atlas
CVE-2026-8609 High

Pre-authentication denial of service via the OAuth login route

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

Exploit probability 0.4%
Published July 14, 2026
Required by Not available
Last source change July 14, 2026

02 / AFFECTED SOFTWARE

Affected packages

Bitnami grafana
Unknown Unknown

14 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-8609

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

View original source
Open Source Vulnerabilities BIT-grafana-2026-8609

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

View original source

05 / REFERENCES

Further evidence