CVE-2026-27878

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*

History

29 Jun 2026, 19:59

Type Values Removed Values Added
First Time Grafana
Grafana tempo
References () https://grafana.com/security/security-advisories/cve-2026-27878 - () https://grafana.com/security/security-advisories/cve-2026-27878 - Broken Link
CPE cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*

23 Jun 2026, 13:16

Type Values Removed Values Added
CWE CWE-400

19 Jun 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-19 19:16

Updated : 2026-06-29 19:59


NVD link : CVE-2026-27878

Mitre link : CVE-2026-27878

CVE.ORG link : CVE-2026-27878


JSON object : View

Products Affected

grafana

  • tempo
CWE
CWE-400

Uncontrolled Resource Consumption