SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2026-21720

Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

HIGH 7.5EPSS 0.64%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.64% probability · 49th percentile
CISA KEV
Not listed
Weakness
CWE-400, CWE-703, CWE-772
Affected
grafana/grafana
Source
security@grafana.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.