CVE-2026-27878

MEDIUM

Tempo TraceQL query with exemplar hint could result in unbounded memory usage

Title source: cna
STIX 2.1

Description

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0041
EPSS Percentile 33.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (3)
Grafana/Enterprise Traces (GET) 2.6.1 - 2.8.8
Grafana/Tempo 2.6.0 - 2.10.2
grafana/tempo 2.6.0 - 2.8.4
Published Jun 19, 2026
Tracked Since Jun 20, 2026