MEDIUM6.5
GHSA-6xff-cpcq-vpw2
Grafana Tempo vulnerable to an out-of-memory crash
Quick fix
GHSA-6xff-cpcq-vpw2 — github.com/grafana/tempo: upgrade to the fixed version with the command below.
go get github.com/grafana/tempo@v1.5.1-0.20260303204923-b13f74291d48Details
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/grafana/tempo
Introduced in:
0Fixed in: 1.5.1-0.20260303204923-b13f74291d48Fix
go get github.com/grafana/tempo@v1.5.1-0.20260303204923-b13f74291d48References
- https://nvd.nist.gov/vuln/detail/CVE-2026-27878[ADVISORY]
- https://github.com/grafana/tempo/pull/6559[WEB]
- https://github.com/grafana/tempo/pull/6646[WEB]
- https://github.com/grafana/tempo/pull/6792[WEB]
- https://github.com/grafana/tempo/pull/6802[WEB]
- https://github.com/grafana/tempo/commit/3d7c78d438890991df594c20ae2031f8934aba3b[WEB]
- https://github.com/grafana/tempo/commit/b13f74291d489672601a10297f8fbcbf7dd19192[WEB]
- https://github.com/grafana/tempo/commit/b481ae9693f99785691197915066e6306950fa09[WEB]
- https://github.com/grafana/tempo/commit/e2d51b786aff94de3319c07994c6a5539b121eb5[WEB]
- https://github.com/grafana/tempo[PACKAGE]
- https://github.com/grafana/tempo/releases/tag/v2.10.2[WEB]
- https://github.com/grafana/tempo/releases/tag/v2.8.4[WEB]
- https://github.com/grafana/tempo/releases/tag/v2.9.2[WEB]
- https://grafana.com/security/security-advisories/cve-2026-27878[WEB]