Skip to content
tempoGHSA-6xff-cpcq-vpw2

Grafana Tempo vulnerable to an out-of-memory crash

Medium6.5CVE-2026-27878 · Published Jun 19, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/grafana/tempo
Go
< 1.5.1-0.20260303204923-b13f74291d481.5.1-0.20260303204923-b13f74291d48
Details and references

More tempo advisories

All
DateAdvisory
Apr 24Grafana Tempo has an Uncontrolled Resource Consumption issue
CVE-2026-21728High7.5fixed in 2.8.4, 2.9.2, 2.10.2
Mar 27Grafana Tempo has Inadequate Encryption Strength
CVE-2026-28377High7.5fixed in 2.10.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.