Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
v12.1.0 (semver) before v12.1.10
affected
v12.2.0 (semver) before v12.2.8
affected
v12.3.0 (semver) before v12.3.6
affected
v12.4.0 (semver) before v12.4.2
affected
Description
The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.
Product status
v12.1.0 (semver) before v12.1.10
v12.2.0 (semver) before v12.2.8
v12.3.0 (semver) before v12.3.6
v12.4.0 (semver) before v12.4.2
References
grafana.com/security/security-advisories/cve-2026-27880
grafana.com/security/security-advisories/cve-2026-27880