Vulnerabilities
Vulnerable Software
Grafana:  >> Tempo  >> 2.10.0  Security Vulnerabilities
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.
CVSS Score
6.5
EPSS Score
0.002
Published
2026-06-19
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.
CVSS Score
7.5
EPSS Score
0.006
Published
2026-04-24
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.
CVSS Score
7.5
EPSS Score
0.002
Published
2026-03-26


Contact Us

Shodan ® - All rights reserved