GHSA-6xff-cpcq-vpw2MediumCVSS 6.5

Grafana Tempo vulnerable to an out-of-memory crash

Published
June 19, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

🎯 Affected products1

  • go/github.com/grafana/tempo:< 1.5.1-0.20260303204923-b13f74291d48

🔗 References (14)