6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Description
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.
Basic Information
ID
CVE-2026-27878
Source
GRAFANA
Published
Jun 19, 2026 at 19:02
Modified
Jun 19, 2026 at 19:03
Affected Product
Vendor
Grafana
Product
Enterprise Traces (GET)
Version
2.6.1
Affected Versions
Grafana Enterprise Traces (GET) 2.6.1
Grafana Tempo 2.6.0
Grafana Tempo 2.6.0