Tempo denial of service via TraceQL exemplars hint (TraceQL query execution)

Medium
Advisory ID:CVE-2026-27878
Published:2026-03-23
Product:Tempo
CVSS Score:6.5
CVSS Vector:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Fixed Versions:
>=2.8.8
>=2.10.2

Summary

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

Tempo OSS is fixed in v2.10.2 and later. Grafana Enterprise Traces (GET) is fixed in v2.8.8 and later. Versions prior to v2.6.0 are not affected.