Skip to content
TempoGHSA-ffqx-q65f-36jf

Grafana Tempo has Inadequate Encryption Strength

High7.5CVE-2026-28377 · Published Mar 27, 2026 · updated Sep 10, 2026

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/grafana/tempo
Go
< 2.10.32.10.3
Details and references

More Tempo advisories

All Tempo
Advisory
Grafana Tempo vulnerable to an out-of-memory crash
Medium6.5Jun 19
Grafana Tempo has an Uncontrolled Resource Consumption issue
High7.5Apr 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.