CVE-2026-21728: Grafana Tempo

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.

Affected products

  • Grafana Tempo: from 1.3.0, before 2.8.4 (fixed in 2.8.4); from 2.9.0, before 2.9.2 (fixed in 2.9.2); from 2.10.0, before 2.10.2 (fixed in 2.10.2)

Published 2026-04-24. Last modified 2026-09-09.