CVE-2026-27879: Query resampling can cause unbounded memory allocations
A resample query can be used to trigger out-of-memory crashes in Grafana.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or avoid using query resampling in Grafana to prevent unbounded memory allocations that can trigger out-of-memory crashes.
Grafana query resampling = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27879?
CVE-2026-27879 is classified as a high-severity vulnerability due to its potential to cause unbounded memory allocations leading to crashes.
How do I fix CVE-2026-27879?
To mitigate CVE-2026-27879, upgrade Grafana to the latest version where the vulnerability has been patched.
What software is affected by CVE-2026-27879?
CVE-2026-27879 specifically affects Grafana Labs Grafana.
What type of attack does CVE-2026-27879 enable?
CVE-2026-27879 allows for attacks that can trigger out-of-memory crashes through malicious resample queries.
Can CVE-2026-27879 be exploited remotely?
Yes, CVE-2026-27879 can be exploited remotely when the vulnerable Grafana instance processes untrusted input.