CVE-2026-28375: Grafana Testdata datasource can issue unbounded memory allocations
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Grafana Testdata datasourcefrom your environment.Remove or uninstall the Testdata datasource from Grafana if it is not required to eliminate the vector that can cause out-of-memory crashes.
- Configuration
Disable the Testdata datasource in Grafana if it is not required to prevent unbounded memory allocations that can trigger out-of-memory crashes.
Grafana Testdata datasource enabled = false
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28375?
The severity of CVE-2026-28375 is considered critical due to the potential for unbounded memory allocations leading to out-of-memory crashes in Grafana.
How do I fix CVE-2026-28375?
To fix CVE-2026-28375, update to the latest version of Grafana that includes the patch addressing this vulnerability.
What are the potential impacts of CVE-2026-28375?
The potential impacts of CVE-2026-28375 include application downtime and denial of service due to out-of-memory conditions.
Who is affected by CVE-2026-28375?
CVE-2026-28375 affects users of the Grafana Testdata datasource where the unbounded memory allocation can be exploited.
When was CVE-2026-28375 reported?
CVE-2026-28375 was reported in 2026, but specific disclosure dates should be verified in official security advisories.