CVE-2026-21728

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-24 09:16

Updated : 2026-09-09 13:18


NVD link : CVE-2026-21728

Mitre link : CVE-2026-21728

CVE.ORG link : CVE-2026-21728


JSON object : View

Products Affected

grafana

  • tempo
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling