Skip to content
tempoGHSA-p4r4-xvrq-gvmc

Grafana Tempo has an Uncontrolled Resource Consumption issue

High7.5CVE-2026-21728 · Published Apr 24, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/grafana/tempo
Go
>= 1.3.0, < 2.8.42.8.4
>= 2.9.0, < 2.9.22.9.2
>= 2.10.0, < 2.10.22.10.2
Details and references

More tempo advisories

All
DateAdvisory
Mar 27Grafana Tempo has Inadequate Encryption Strength
CVE-2026-28377High7.5fixed in 2.10.3
Jun 19Grafana Tempo vulnerable to an out-of-memory crash
CVE-2026-27878Medium6.5fixed in 1.5.1-0.20260303204923-b13f74291d48

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.