CVE-2026-27878

Updated on 19 Jun 2026

Severity

6.5 Medium severity

Details

CVSS score
6.5
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

Details

Affected product:
Grafana , grafana/tempo
Affected packages:
github.com/grafana/tempo @ 1.5.1-0.20240604192202-01f4bc8ac2d1 (+7 more)