Grafana published security advisories for two products, including CVE-2026-15583 in Grafana MCP Server and a separate unbounded memory allocation issue in Grafana Loki. The MCP Server flaw affects version 0.17.1 and earlier and stems from a confused-deputy SSRF condition triggered through the X-Grafana-URL header. An unauthenticated remote attacker can use the bug to exfiltrate the server’s environment-configured Grafana service-account token and force requests to arbitrary internal services.
The SSRF exposure also extends to sensitive internal targets such as cloud metadata endpoints, raising the risk of credential theft and internal network access without user interaction. Grafana’s Loki advisory covers version 3.7.0 and earlier, where detected_fields query limits can cause unbounded memory allocation. Government and security notices have urged administrators to review Grafana’s advisories and apply the vendor’s updates for affected MCP Server and Loki deployments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-15, Grafana published security advisories covering an SSRF issue in Grafana MCP Server and an unbounded memory allocation issue in Grafana Loki. The advisories identify affected versions as Grafana MCP Server 0.17.1 and earlier and Grafana Loki 3.7.0 and earlier.
The CVE entry states that CVE-2026-15583 was received by security@grafana.com on 2026-07-15. The flaw affects Grafana MCP Server up to and including version 0.17.1 and allows SSRF and exfiltration of the configured Grafana service-account token via a crafted X-Grafana-URL header.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.