Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18).
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p4r4-xvrq-gvmc | Grafana Tempo has an Uncontrolled Resource Consumption issue |
Fri, 01 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 28 Apr 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grafana
Grafana tempo |
|
| Vendors & Products |
Grafana
Grafana tempo |
Fri, 24 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
ssvc
|
Fri, 24 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). | |
| Title | Tempo query limit results in unbounded memory allocation | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2026-05-13T19:28:30.906Z
Reserved: 2026-01-05T09:26:06.215Z
Link: CVE-2026-21728
Updated: 2026-04-24T11:33:33.468Z
Status : Awaiting Analysis
Published: 2026-04-24T09:16:03.710
Modified: 2026-04-24T14:39:28.770
Link: CVE-2026-21728
OpenCVE Enrichment
Updated: 2026-05-01T05:45:10Z
Github GHSA