tempoGHSA-6xff-cpcq-vpw2
Grafana Tempo vulnerable to an out-of-memory crash
Medium6.5CVE-2026-27878 · Published Jun 19, 2026 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/grafana/tempo Go | < 1.5.1-0.20260303204923-b13f74291d48 | 1.5.1-0.20260303204923-b13f74291d48 |
Details and references
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- CVE-2026-27878, GO-2026-6325
- nvd.nist.gov/vuln/detail/CVE-2026-27878
- github.com/grafana/tempo/pull/6559
- github.com/grafana/tempo/pull/6646
- github.com/grafana/tempo/pull/6792
- github.com/grafana/tempo/pull/6802
- github.com/grafana/tempo/commit/3d7c78d438890991df594c20ae2031f8934aba3b
- github.com/grafana/tempo/commit/b13f74291d489672601a10297f8fbcbf7dd19192
- github.com/grafana/tempo/commit/b481ae9693f99785691197915066e6306950fa09
- github.com/grafana/tempo/commit/e2d51b786aff94de3319c07994c6a5539b121eb5
- github.com/grafana/tempo
- github.com/grafana/tempo/releases/tag/v2.10.2
- github.com/grafana/tempo/releases/tag/v2.8.4
- github.com/grafana/tempo/releases/tag/v2.9.2
- grafana.com/security/security-advisories/cve-2026-27878
More tempo advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 24 | Grafana Tempo has an Uncontrolled Resource Consumption issue CVE-2026-21728High7.5fixed in 2.8.4, 2.9.2, 2.10.2 | High7.5 | 2.8.4, 2.9.2, 2.10.2 |
| Mar 27 | Grafana Tempo has Inadequate Encryption Strength CVE-2026-28377High7.5fixed in 2.10.3 | High7.5 | 2.10.3 |