HarborGuard / CVE
Back to search
HIGHCVE-2026-27880Published Modified CNA GRAFANA

CVE-2026-27880: OpenFeature evaluation API reads input data with no bounds

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
v12.1.10
Affected Products
1

Fix available

v12.1.10v12.2.8v12.3.6v12.4.2
Affected packages
  • Grafana / Grafana
    < v12.1.10 (from v12.1.0) · < v12.2.8 (from v12.2.0) · < v12.3.6 (from v12.3.0) · < v12.4.2 (from v12.4.0)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References