HIGHGo →
Grafana Tempo vulnerable to an out-of-memory crash
Grafana Tempo vulnerable to an out-of-memory crash
Affected packages
- github.com/grafana/tempo
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2026-27878
- https://github.com/grafana/tempo/pull/6559
- https://github.com/grafana/tempo/pull/6646
- https://github.com/grafana/tempo/pull/6792
- https://github.com/grafana/tempo/pull/6802
- https://github.com/grafana/tempo/commit/3d7c78d438890991df594c20ae2031f8934aba3b
- https://github.com/grafana/tempo/commit/b13f74291d489672601a10297f8fbcbf7dd19192
- https://github.com/grafana/tempo/commit/b481ae9693f99785691197915066e6306950fa09
- https://github.com/grafana/tempo/commit/e2d51b786aff94de3319c07994c6a5539b121eb5
- https://github.com/grafana/tempo
- https://github.com/grafana/tempo/releases/tag/v2.10.2
- https://github.com/grafana/tempo/releases/tag/v2.8.4
- https://github.com/grafana/tempo/releases/tag/v2.9.2
- https://grafana.com/security/security-advisories/cve-2026-27878
Structured record: https://osv.dev/vulnerability/GHSA-6xff-cpcq-vpw2
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta