VDB
BIT-grafana-2026-21720
BIT-grafana-2026-21720
PUBLISHED
CVSS 7.5 HIGH
Unauthenticated DoS: avatar cache leaks goroutines when /avatar/:hash requests time out
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | grafana | 3.0.0, 12.0.0, 12.1.0 |
Timeline
- Feb 18, 2026 CVE Published
- Jul 6, 2026 CVE Updated
References
- https://grafana.com/security/security-advisories/CVE-2026-21720 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-21720 url
- https://grafana.com/security/security-advisories/cve-2026-21720 url
- https://access.redhat.com/security/cve/CVE-2026-21720 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2433226 url
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21720.json url