VYPR
Medium severity6.5NVD Advisory· Published Jun 19, 2026· Updated Jun 29, 2026

CVE-2026-27878

CVE-2026-27878

Description

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/grafana/tempoGo
< 1.5.1-0.20260303204923-b13f74291d481.5.1-0.20260303204923-b13f74291d48

Affected products

8

Patches

Vulnerability mechanics

References

14

News mentions

0

No linked articles in our index yet.