Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1376 articles · 105530 vulns · 38/41 feeds (7d)
← Back to list
7.5
CVE-2026-27880EXPLOITED
grafana · grafana

OpenFeature evaluation API reads input data with no bounds

Description

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

Affected Products

VendorProductVersions
grafanagrafanav12.1.0, v12.2.0, v12.3.0, v12.4.0

References

  • https://grafana.com/security/security-advisories/cve-2026-27880(vendor-advisory)

Related News (2 articles)

Tier C
VulDB6h ago
CVE-2026-27880 | Grafana up to 12.1.9/12.2.7/12.3.5/12.4.1 OpenFeature denial of service
→ No new info (linked only)
Tier B
CCCS Canada1d ago
Grafana security advisory (AV26-285)
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Published3/27/2026
Last enriched5h agov2
Tags
cross-site-scriptinginformation-disclosuregrafanadenial-of-serviceprivilege-escalation
Trending Score66
Source articles2
Independent2
Info Completeness11/14
Missing: epss, kev, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Version History

v2
Last enriched 5h ago
v2Tier C5h ago

Updated affected versions to include 12.1.9, 12.2.7, 12.3.5, and 12.4.1, changed severity to MEDIUM, and added patch available version 12.1.9.

affectedVersionsseveritypatchAvailable
via VulDB
v16h ago

Initial creation