CVE-2026-28377: Grafana Tempo
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.
Affected products
- Grafana Tempo: before 2.10.3 (fixed in 2.10.3)
Published 2026-03-26. Last modified 2026-06-17.