CVE 7.5 HIGH

Tempo query limit results in unbounded memory allocation_CVE-2026-21728

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18).

Basic Information

ID CVE-2026-21728
Source GRAFANA
Published Apr 24, 2026 at 08:00

Affected Product

Vendor Grafana
Product Tempo
Version v1.3.0
Affected Versions Grafana Tempo v1.3.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.