CVE 6.5 MEDIUM

Tempo TraceQL query with exemplar hint could result in unbounded memory usage_CVE-2026-27878

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Description

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

Basic Information

ID CVE-2026-27878
Source GRAFANA
Published Jun 19, 2026 at 19:02
Modified Jun 19, 2026 at 19:03

Affected Product

Vendor Grafana
Product Enterprise Traces (GET)
Version 2.6.1
Affected Versions Grafana Enterprise Traces (GET) 2.6.1
Grafana Tempo 2.6.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.