CVE-2026-21728

HIGH

Tempo query limit results in unbounded memory allocation

Title source: cna
STIX 2.1

Description

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.

Scores

CVSS v3 7.5
EPSS 0.0064
EPSS Percentile 47.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400 CWE-770
Status published
Products (7)
Grafana/Enterprise Traces (GET) 1.0.0 - 2.8.7
Grafana/Tempo 1.3.0 - 2.8.3
grafana/tempo 1.3.0 - 2.8.4Go
grafana/tempo 1.3.0 - 2.8.4
Grafana/Tempo 2.10.0 - 2.10.1
Grafana/Tempo 2.9.0 - 2.9.1
Grafana/Tempo v1.3.0 - v2.11.0
Published Apr 24, 2026
Tracked Since Apr 24, 2026