Medium severity6.5NVD Advisory· Published Jun 19, 2026· Updated Jun 29, 2026
CVE-2026-27878
CVE-2026-27878
Description
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/grafana/tempoGo | < 1.5.1-0.20260303204923-b13f74291d48 | 1.5.1-0.20260303204923-b13f74291d48 |
Affected products
8- osv-coords6 versionspkg:apk/chainguard/grafana-12.4pkg:apk/wolfi/grafana-12.4pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:apk/chainguard/grafana-fips-13.0pkg:apk/chainguard/commercial-grafana-12.4pkg:apk/chainguard/grafana-fips-12.4
< 12.4.9-r4+ 5 more
- (no CPE)range: < 12.4.9-r4
- (no CPE)range: < 12.4.9-r4
- (no CPE)range: < 0.0.20260902T191204-160000.1.1
- (no CPE)range: < 13.0.7-r2
- (no CPE)range: < 12.4.10-r0
- (no CPE)range: < 12.4.10-r0
Patches
Vulnerability mechanics
References
14- github.com/advisories/GHSA-6xff-cpcq-vpw2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-27878ghsaADVISORY
- github.com/grafana/tempo/commit/3d7c78d438890991df594c20ae2031f8934aba3bghsaWEB
- github.com/grafana/tempo/commit/b13f74291d489672601a10297f8fbcbf7dd19192ghsaWEB
- github.com/grafana/tempo/commit/b481ae9693f99785691197915066e6306950fa09ghsaWEB
- github.com/grafana/tempo/commit/e2d51b786aff94de3319c07994c6a5539b121eb5ghsaWEB
- github.com/grafana/tempo/pull/6559ghsaWEB
- github.com/grafana/tempo/pull/6646ghsaWEB
- github.com/grafana/tempo/pull/6792ghsaWEB
- github.com/grafana/tempo/pull/6802ghsaWEB
- github.com/grafana/tempo/releases/tag/v2.10.2ghsaWEB
- github.com/grafana/tempo/releases/tag/v2.8.4ghsaWEB
- github.com/grafana/tempo/releases/tag/v2.9.2ghsaWEB
- grafana.com/security/security-advisories/cve-2026-27878nvdBroken LinkWEB
News mentions
0No linked articles in our index yet.