CVE-2026-21728

Source
https://cve.org/CVERecord?id=CVE-2026-21728
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21728.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-21728
Aliases
Downstream
Related
Published
2026-04-24T08:00:47.074Z
Modified
2026-07-25T03:56:13.987375057Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Tempo query limit results in unbounded memory allocation
Details

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

Mitigation can be done by setting maxresultlimit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21728.json",
    "cna_assigner": "GRAFANA",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.3.0"
                },
                {
                    "last_affected": "2.8.3"
                },
                {
                    "introduced": "2.9.0"
                },
                {
                    "last_affected": "2.9.1"
                },
                {
                    "introduced": "2.10.0"
                },
                {
                    "last_affected": "2.10.1"
                },
                {
                    "introduced": "1.0.0"
                },
                {
                    "last_affected": "2.8.7"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/grafana/tempo

Affected ranges

Type
GIT
Repo
https://github.com/grafana/tempo
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.3.0"
        },
        {
            "fixed": "2.8.4"
        },
        {
            "introduced": "2.9.0"
        },
        {
            "fixed": "2.9.2"
        },
        {
            "introduced": "2.10.0"
        },
        {
            "fixed": "2.10.2"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*"
}

Affected versions

v1.*
v1.3.0
v1.4.0
v1.4.0-rc.0
v1.5.0
v1.5.0-rc.0
v1.5.0-rc.1
v1.5.0-rc.2
v2.*
v2.0.0
v2.0.0-rc.0
v2.1.0-rc.0
v2.10.0
v2.10.1
v2.2.0-rc.0
v2.3.0-rc.0
v2.4.0
v2.4.0-rc.0
v2.5.0-rc.0
v2.5.0-rc.1
v2.6.0-rc.0
v2.7.0-rc.0
v2.8.0
v2.8.0-rc.0
v2.8.0-rc.1
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21728.json"