Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p4r4-xvrq-gvmc

Опубликовано: 24 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Grafana Tempo has an Uncontrolled Resource Consumption issue

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18).

Пакеты

Наименование

github.com/grafana/tempo

go
Затронутые версииВерсия исправления

>= 1.3.0, < 2.8.4

2.8.4

Наименование

github.com/grafana/tempo

go
Затронутые версииВерсия исправления

>= 2.9.0, < 2.9.2

2.9.2

Наименование

github.com/grafana/tempo

go
Затронутые версииВерсия исправления

>= 2.10.0, < 2.10.2

2.10.2

EPSS

Процентиль: 47%
0.00637
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
redhat
3 месяца назад

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.

CVSS3: 7.5
nvd
3 месяца назад

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.

CVSS3: 7.5
redos
около 1 месяца назад

Уязвимость tempo

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость программного обеспечения для хранения и анализа распределенных трассировок Grafana Tempo, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 47%
0.00637
Низкий

7.5 High

CVSS3

Дефекты

CWE-400