GHSA-6xff-cpcq-vpw2MediumCVSS 6.5
Grafana Tempo vulnerable to an out-of-memory crash
🔗 CVE IDs covered (1)
📋 Description
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.
🎯 Affected products1
- go/github.com/grafana/tempo:< 1.5.1-0.20260303204923-b13f74291d48
🔗 References (14)
- https://nvd.nist.gov/vuln/detail/CVE-2026-27878
- https://grafana.com/security/security-advisories/cve-2026-27878
- https://github.com/grafana/tempo/pull/6559
- https://github.com/grafana/tempo/pull/6646
- https://github.com/grafana/tempo/pull/6792
- https://github.com/grafana/tempo/pull/6802
- https://github.com/grafana/tempo/commit/3d7c78d438890991df594c20ae2031f8934aba3b
- https://github.com/grafana/tempo/commit/b13f74291d489672601a10297f8fbcbf7dd19192
- https://github.com/grafana/tempo/commit/b481ae9693f99785691197915066e6306950fa09
- https://github.com/grafana/tempo/commit/e2d51b786aff94de3319c07994c6a5539b121eb5
- https://github.com/grafana/tempo/releases/tag/v2.10.2
- https://github.com/grafana/tempo/releases/tag/v2.8.4
- https://github.com/grafana/tempo/releases/tag/v2.9.2
- https://github.com/advisories/GHSA-6xff-cpcq-vpw2