Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-21728

Опубликовано: 24 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.

A flaw was found in Tempo. A remote attacker can exploit this vulnerability by sending large queries to the Tempo service. This can lead to excessive memory allocations, potentially causing a Denial of Service (DoS) by impacting the availability of the service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Not affected
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Not affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Affected
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Affected
Red Hat Ceph Storage 9rhceph/grafana-rhel10Affected
Red Hat Enterprise Linux 10grafanaNot affected
Red Hat Enterprise Linux 9grafanaNot affected
Red Hat OpenShift distributed tracing 3rhosdt/tempo-gateway-rhel9Affected
Red Hat OpenShift distributed tracing 3rhosdt/tempo-query-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2461395grafana/tempo: Tempo: Denial of Service via large queries

EPSS

Процентиль: 47%
0.00645
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.

CVSS3: 7.5
redos
около 1 месяца назад

Уязвимость tempo

CVSS3: 7.5
github
3 месяца назад

Grafana Tempo has an Uncontrolled Resource Consumption issue

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость программного обеспечения для хранения и анализа распределенных трассировок Grafana Tempo, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 47%
0.00645
Низкий

7.5 High

CVSS3