Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-21723

CVE-2026-21723: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium5.3

    Medium [CVE-2026-21723] Denial of Service via uncontrolled memory usage in alertmanager templates

    CVE-2026-21723Source published Source updated

    The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled. A flaw was found in Grafana. This can lead to an Out-Of-Memory (OOM) error, causing the Grafana service to crash and resulting in a Denial of Service (DoS). This Moderate flaw in Grafana allows a remote attacker to trigger a Denial of Service by repeatedly executing alertmanager templates. While requiring low privileges, or anonymous access if enabled, the high attack complexity limits the immediate threat, as it relies on exhausting memory through mass template…

    Affected products in this advisory
    • Multicluster Global Hub
    • Red Hat Advanced Cluster Management for Kubernetes 2
    • Red Hat Ceph Storage 5
    • Red Hat Ceph Storage 6

    7 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • If not required, disable anonymous access to prevent unauthenticated exploitation of the Alertmanager templates test endpoint. Refer to Grafana’s official documentation for configuration details. To protect against low-privileged authenticated users triggering this flaw, configure a reverse proxy or WAF to block or strictly rate-limit traffic to /api/alertmanager/grafana/config/api/v1/templates/test.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery