๐Ÿ” CVE Alert

CVE-2026-27878

MEDIUM 6.5

Tempo TraceQL query with exemplar hint could result in unbounded memory usage

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

Vendor grafana
Product enterprise traces (get)
Ecosystems
Industries
Technology
Published Jun 19, 2026
Last Updated Jun 19, 2026
Stay Ahead of the Next One

Get instant alerts for grafana enterprise traces (get)

Be the first to know when new medium vulnerabilities affecting grafana enterprise traces (get) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Grafana / Enterprise Traces (GET)
2.6.1 < 2.8.8
Grafana / Tempo
2.6.0 < 2.10.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
grafana.com: https://grafana.com/security/security-advisories/cve-2026-27878