CVE-2026-27878: Grafana Tempo vulnerable to an out-of-memory crash
(updated )
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.
References
- github.com/advisories/GHSA-6xff-cpcq-vpw2
- github.com/grafana/tempo/commit/3d7c78d438890991df594c20ae2031f8934aba3b
- github.com/grafana/tempo/commit/b13f74291d489672601a10297f8fbcbf7dd19192
- github.com/grafana/tempo/commit/b481ae9693f99785691197915066e6306950fa09
- github.com/grafana/tempo/commit/e2d51b786aff94de3319c07994c6a5539b121eb5
- github.com/grafana/tempo/pull/6559
- github.com/grafana/tempo/pull/6646
- github.com/grafana/tempo/pull/6792
- github.com/grafana/tempo/pull/6802
- github.com/grafana/tempo/releases/tag/v2.10.2
- github.com/grafana/tempo/releases/tag/v2.8.4
- github.com/grafana/tempo/releases/tag/v2.9.2
- grafana.com/security/security-advisories/cve-2026-27878
- nvd.nist.gov/vuln/detail/CVE-2026-27878
Code Behaviors & Features
Detect and mitigate CVE-2026-27878 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →