Showing 2 vulnerabilities on this page for Enterprise Traces (GET)

Signals CISA KEV Ransomware Nuclei
Grafana vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Tempo TraceQL query with exemplar hint could result in unbounded memory usage

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

CWE-400Jun 19, 2026
CVSS6.5v3.1EPSS0.411%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Tempo query limit results in unbounded memory allocation

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.

CWE-400CWE-770Apr 24, 2026
CVSS7.5v3.1EPSS0.637%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX