CVE-2026-21728

EUVD-2026-25408
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 46%
Affected Products (NVD)
VendorProductVersion
grafanatempo
1.3.0 ≤
𝑥
< 2.8.4
grafanatempo
2.9.0 ≤
𝑥
< 2.9.2
grafanatempo
2.10.0 ≤
𝑥
< 2.10.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatMulticluster Global Hub 1.3.4
1779212259 ≤
𝑥
< *
ADP
Red HatMulticluster Global Hub 1.4.5
1779579439 ≤
𝑥
< *
ADP
Red HatMulticluster Global Hub 1.5.6
1778867753 ≤
𝑥
< *
ADP
Red HatMulticluster Global Hub 1.6.2
1780167118 ≤
𝑥
< *
ADP
Red HatMulticluster Global Hub 1.7.0
1779925273 ≤
𝑥
< *
ADP