CVE-2026-28379Disclosed before NVD

Viewer-triggered race condition in Grafana Live leads to complete server crash

Published
May 13, 2026
Last Modified

📋 Description

A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete service unavailability requiring restart of the Grafana server. This vulnerability was reported via our bug bounty program.

🎯 Affected products1

  • Grafana

🔗 References (1)