tempoGHSA-p4r4-xvrq-gvmc
Grafana Tempo has an Uncontrolled Resource Consumption issue
High7.5CVE-2026-21728 · Published Apr 24, 2026 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/grafana/tempo Go | >= 1.3.0, < 2.8.4 | 2.8.4 |
| >= 2.9.0, < 2.9.2 | 2.9.2 | |
| >= 2.10.0, < 2.10.2 | 2.10.2 |
Details and references
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18).
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- CVE-2026-21728, GO-2026-5528
- nvd.nist.gov/vuln/detail/CVE-2026-21728
- github.com/grafana/tempo/pull/6525
- github.com/grafana/tempo/commit/650eb1985a0776789c8564122990f588a742356f
- github.com/grafana/tempo
- github.com/grafana/tempo/blob/4dc3e5b0d3463a0b67498b662b85a148698b4afd/docs/sources/tempo/release-notes/version-2/v2-10.md?plain=1#L328
- github.com/grafana/tempo/blob/4dc3e5b0d3463a0b67498b662b85a148698b4afd/docs/sources/tempo/release-notes/version-2/v2-8.md?plain=1#L251
- github.com/grafana/tempo/blob/4dc3e5b0d3463a0b67498b662b85a148698b4afd/docs/sources/tempo/release-notes/version-2/v2-9.md?plain=1#L224
- grafana.com/security/security-advisories/cve-2026-21728
More tempo advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 27 | Grafana Tempo has Inadequate Encryption Strength CVE-2026-28377High7.5fixed in 2.10.3 | High7.5 | 2.10.3 |
| Jun 19 | Grafana Tempo vulnerable to an out-of-memory crash CVE-2026-27878Medium6.5fixed in 1.5.1-0.20260303204923-b13f74291d48 | Medium6.5 | 1.5.1-0.20260303204923-b13f74291d48 |