CVE-2026-21729: Loki detected_fields query limits results in unbounded memory allocation
Published Jul 16, 2026
·Updated
Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.
Affected Software
1 affected component
Grafana Loki
Event History
Jul 16, 2026
CVE Published
via MITRE·03:12 AM
Data Sourced
via MITRE·03:12 AM
DescriptionSeverity
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-21729?
The severity of CVE-2026-21729 is rated as high with a score of 7.5.
2
What is CVE-2026-21729 about?
CVE-2026-21729 pertains to Loki's detected_fields query allowing for unbounded memory allocation with large query limits.
3
How can CVE-2026-21729 impact a deployed service?
CVE-2026-21729 can impact service availability due to excessive memory allocation from large query limits.
4
How can I mitigate the risk of CVE-2026-21729?
To mitigate CVE-2026-21729, it is recommended to implement query limit restrictions and monitor memory usage.
5
Which software is affected by CVE-2026-21729?
CVE-2026-21729 affects Grafana Loki.