PT-2026-34868 · Grafana+1 · Tempo+1

CVE-2026-21728

·

Published

2026-02-20

·

Updated

2026-08-14

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Grafana Tempo versions prior to 2.8.4 Grafana Tempo versions 2.9.0 through 2.9.1 Grafana Tempo versions 2.10.0 through 2.10.1
Description An uncontrolled resource consumption issue exists where queries with large limits can trigger excessive memory allocations. This may allow a remote attacker to cause a denial of service, impacting the availability of the service depending on the deployment strategy.
Recommendations Update to version 2.8.4 or later. Update to version 2.9.2 or later. Update to version 2.10.2 or later. Set max result limit in the search configuration to 262144 (2^18). Configure the service to restart automatically.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09518
CLEANSTART-2026-GX27419
CLEANSTART-2026-IE49312
CLEANSTART-2026-LC55153
CLEANSTART-2026-ZZ38071
CVE-2026-21728
GHSA-P4R4-XVRQ-GVMC
GO-2026-5528
OPENSUSE-SU-2026:21483-1

Affected Products

Red Os
Tempo