PT-2026-34868 · Grafana+1 · Tempo+1
CVE-2026-21728
·
Published
2026-02-20
·
Updated
2026-08-14
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Grafana Tempo versions prior to 2.8.4
Grafana Tempo versions 2.9.0 through 2.9.1
Grafana Tempo versions 2.10.0 through 2.10.1
Description
An uncontrolled resource consumption issue exists where queries with large limits can trigger excessive memory allocations. This may allow a remote attacker to cause a denial of service, impacting the availability of the service depending on the deployment strategy.
Recommendations
Update to version 2.8.4 or later.
Update to version 2.9.2 or later.
Update to version 2.10.2 or later.
Set
max result limit in the search configuration to 262144 (2^18).
Configure the service to restart automatically.Exploit
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Os
Tempo