Looking for the vulnerability index of Invicti's legacy products?
Grafana Uncontrolled Resource Consumption Vulnerability (CVE-2026-33378) - Vulnerability Database

Grafana Uncontrolled Resource Consumption Vulnerability (CVE-2026-33378)

Description

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

References

Related Vulnerabilities