Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1359 articles · 105469 vulns · 38/41 feeds (7d)
← Back to list
7.5
CVE-2026-27880EXPLOITED
grafana · grafana

OpenFeature evaluation API reads input data with no bounds

Description

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

Affected Products

VendorProductVersions
grafanagrafanav12.1.0, v12.2.0, v12.3.0, v12.4.0

References

  • https://grafana.com/security/security-advisories/cve-2026-27880(vendor-advisory)

Related News (2 articles)

Tier C
VulDB4h ago
CVE-2026-27880 | Grafana up to 12.1.9/12.2.7/12.3.5/12.4.1 OpenFeature denial of service
→ No new info (linked only)
Tier B
CCCS Canada23h ago
Grafana security advisory (AV26-285)
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Published3/27/2026
Last enriched3h agov2
Tags
cross-site-scriptinginformation-disclosuregrafanadenial-of-serviceprivilege-escalation
Trending Score56
Source articles2
Independent2
Info Completeness11/14
Missing: epss, kev, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Version History

v2
Last enriched 3h ago
v2Tier C3h ago

Updated affected versions to include 12.1.9, 12.2.7, 12.3.5, and 12.4.1, changed severity to MEDIUM, and added patch available version 12.1.9.

affectedVersionsseveritypatchAvailable
via VulDB
v14h ago

Initial creation