A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

Project Subscriptions

Vendors Products
Grafana Subscribe
Enterprise Metrics Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 24 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Grafana
Grafana enterprise Metrics
Grafana tempo
Vendors & Products Grafana
Grafana enterprise Metrics
Grafana tempo

Mon, 22 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 19 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Fri, 19 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Description A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.
Title Tempo TraceQL query with exemplar hint could result in unbounded memory usage
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GRAFANA

Published:

Updated: 2026-07-24T12:23:12.625Z

Reserved: 2026-02-24T14:30:17.726Z

Link: CVE-2026-27878

cve-icon Vulnrichment

Updated: 2026-06-22T17:09:58.772Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T20:30:04Z

Weaknesses