A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.
References
| Link | Resource |
|---|---|
| https://grafana.com/security/security-advisories/cve-2026-27878 | Broken Link |
Configurations
Configuration 1 (hide)
|
History
29 Jun 2026, 19:59
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Grafana
Grafana tempo |
|
| References | () https://grafana.com/security/security-advisories/cve-2026-27878 - Broken Link | |
| CPE | cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:* |
23 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-400 |
19 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-19 19:16
Updated : 2026-06-29 19:59
NVD link : CVE-2026-27878
Mitre link : CVE-2026-27878
CVE.ORG link : CVE-2026-27878
JSON object : View
Products Affected
grafana
- tempo
CWE
CWE-400
Uncontrolled Resource Consumption
