CVE-2026-27878
EUVD-2026-3806619.06.2026, 19:16
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| grafana | tempo | 2.6.0 ≤ 𝑥 < 2.8.4 |
| grafana | tempo | 2.9.0 ≤ 𝑥 < 2.9.2 |
| grafana | tempo | 2.10.0 ≤ 𝑥 < 2.10.2 |
𝑥
= Vulnerable software versions