CVE-2026-21728

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*

History

13 Jul 2026, 14:16

Type Values Removed Values Added
Summary (en) Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). (en) Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.

30 Jun 2026, 03:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:21769 -
  • () https://access.redhat.com/errata/RHSA-2026:22347 -
  • () https://access.redhat.com/errata/RHSA-2026:22423 -
  • () https://access.redhat.com/errata/RHSA-2026:23345 -
  • () https://access.redhat.com/errata/RHSA-2026:24503 -
  • () https://access.redhat.com/security/cve/CVE-2026-21728 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2461395 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21728.json -
CWE CWE-770

29 Jun 2026, 19:44

Type Values Removed Values Added
First Time Grafana
Grafana tempo
CPE cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*
References () https://grafana.com/security/security-advisories/cve-2026-21728 - () https://grafana.com/security/security-advisories/cve-2026-21728 - Broken Link

24 Apr 2026, 14:16

Type Values Removed Values Added
CWE CWE-400

24 Apr 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-24 09:16

Updated : 2026-07-30 12:17


NVD link : CVE-2026-21728

Mitre link : CVE-2026-21728

CVE.ORG link : CVE-2026-21728


JSON object : View

Products Affected

grafana

  • tempo
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling