Medium [CVE-2026-8609] Denial of Service via unbounded memory growth in OAuth login route
This medium-severity Red Hat Linux advisory covers CVE-2026-8609 affecting Red Hat Enterprise Linux 10, Red Hat Ceph Storage 9, Red Hat package: grafana.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service). A flaw was found in Grafana.
This results in a denial of service for legitimate users. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Ceph Storage 9.
Red Hat fixing advisory: RHSA-2026:54178.
Affected products named by the advisory: Red Hat package: grafana.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 6 days ago·verify at source
- grafana-0:10.2.6-28.el10_2.4
- RHSA-2026:54178
Official advisory · high-confidence parse· fetched 6 days ago·verify at source
Mitigation checklist
- To mitigate this issue, restrict network access to the Grafana instance to trusted internal networks or localhost. If a reverse proxy or load balancer is deployed in front of Grafana, configure it to implement rate limiting on requests to the OAuth login endpoint to prevent an attacker from exhausting system resources. If OAuth is not required, consider disabling it in the Grafana configuration, though this may impact user authentication workflows.
Official advisory · high-confidence parse· fetched 6 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.