CVE-2026-33378 Details
Description
Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.
A vulnerability exists in Grafana when using the SQL datasource with the $__timeGroup macro, leading to a denial-of-service condition by overloading the server. This issue can cause the server to crash, taking over half an hour to recover, unless the server is configured to auto-restart, in which case the impact is minimal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://grafana.com/security/security-advisories/cve-2026-33378 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| grafana grafana | >= 8.0.0, < 11.6.14 >= 12.0.0, < 12.2.8 >= 12.3.0, < 12.3.6 >= 12.4.0, < 12.4.3 11.6.14 - 11.6.14 security01 12.2.8 - 12.2.8 security01 12.3.6 - 12.3.6 security01 12.4.3 - 13.0.0 13.0.1 - |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | Initial Analysis | [email protected] |
| May 14, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |