
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27880 is a denial-of-service vulnerability in Grafana's OpenFeature feature toggle evaluation endpoint that reads unbounded values into memory, causing out-of-memory (OOM) crashes. It affects Grafana versions before v12.1.10 (in the v12.1.x line), before v12.2.8 (v12.2.x), before v12.3.6 (v12.3.x), and before v12.4.2 (v12.4.x). The vulnerability was published on March 27, 2026, with patches released shortly after. It carries a CVSS v3.1 base score of 7.5 (High) (Grafana Advisory, Grafana Blog).
The root cause is the absence of input size limits on the OpenFeature feature toggle evaluation endpoint, classified under CWE-787 (Out-of-bounds Write) and CWE-125 (Out-of-bounds Read). An unauthenticated remote attacker can send crafted HTTP requests with arbitrarily large payloads to this endpoint; the server reads the unbounded data into memory without enforcing any cap, exhausting available memory and triggering an OOM crash. No authentication or special privileges are required, and the attack complexity is low, making this straightforward to exploit over the network (Grafana Advisory).
Successful exploitation results in a complete denial of service for the affected Grafana instance — the process crashes due to memory exhaustion, making dashboards, alerting, and all Grafana functionality unavailable until the service is restarted. There is no confidentiality or integrity impact; only availability is affected. Organizations relying on Grafana for critical monitoring and observability pipelines face significant operational disruption if exploited (Grafana Advisory, Grafana Blog).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.013% (0.000130), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Nessus (plugin 304086) and Qualys (plugin 733926) (Grafana Advisory).
curl or a custom script. The server reads the entire payload into memory without enforcing size limits./var/log/syslog or journalctl); kernel OOM killer messages referencing the Grafana process.Grafana has released patched versions addressing this vulnerability: v12.1.10 or later (for v12.1.x), v12.2.8 or later (for v12.2.x), v12.3.6 or later (for v12.3.x), and v12.4.2 or later (for v12.4.x). Administrators should prioritize upgrading instances running versions prior to these fixed releases. As a temporary workaround while patches are deployed, implement network-level controls (e.g., WAF rules or reverse proxy configuration) to enforce request size limits on the feature toggle evaluation endpoint, and monitor system memory usage to detect and respond to potential exploitation attempts (Grafana Advisory, Grafana Blog).
Grafana published a dedicated security advisory and blog post covering both CVE-2026-27880 and the co-disclosed critical RCE vulnerability CVE-2026-27876, drawing significant community attention. The r/blueteamsec subreddit and corresponding Bluesky posts highlighted the release, with the community noting the combination of a critical RCE and a high-severity DoS in the same release cycle as particularly noteworthy. Security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and SecurityBoulevard covered the vulnerabilities, with most coverage focusing primarily on the more severe RCE (CVE-2026-27876) while noting CVE-2026-27880 as an accompanying high-severity DoS risk (Grafana Blog, GBHackers, SecurityOnline).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."