Vulnerability Bulletins

CVE-2026-27878

   
Affected software GRAFANA
 
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-27878