{"id":"CVE-2026-21728","summary":"Tempo query limit results in unbounded memory allocation","details":"Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.\n\nMitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.","aliases":["GHSA-p4r4-xvrq-gvmc","GO-2026-5528"],"modified":"2026-07-25T03:56:13.987375057Z","published":"2026-04-24T08:00:47.074Z","related":["CGA-chwc-rc6r-v5hf"],"database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.3.0"},{"last_affected":"2.8.3"},{"introduced":"2.9.0"},{"last_affected":"2.9.1"},{"introduced":"2.10.0"},{"last_affected":"2.10.1"},{"introduced":"1.0.0"},{"last_affected":"2.8.7"}]}],"cna_assigner":"GRAFANA","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21728.json"},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21728.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21769"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22347"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22423"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:23345"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24503"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-21728"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21728.json"},{"type":"ADVISORY","url":"https://grafana.com/security/security-advisories/cve-2026-21728"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21728"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2461395"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grafana/tempo","events":[{"introduced":"be6476d9a1d171055f284c434f3432615258ca1c"},{"fixed":"8ce8017366bc1106b75c20864f200ad84f649515"},{"introduced":"607c7fb69662262bbb4462da1e2d91067dab6785"},{"fixed":"f9ce27b87f3f95d1d4533cef143e360be0c4a829"},{"introduced":"5773eb8b0bdd4439a6c065e54f777e4f77d419a1"},{"fixed":"9ce71d29b791b6a3ee7397038a85d8afc3a250fd"}],"database_specific":{"cpe":"cpe:2.3:a:grafana:tempo:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.3.0"},{"fixed":"2.8.4"},{"introduced":"2.9.0"},{"fixed":"2.9.2"},{"introduced":"2.10.0"},{"fixed":"2.10.2"}],"source":"CPE_RANGE"}}],"versions":["v2.10.1","v2.10.0","v2.9.1","v2.8.3","v2.8.2","v2.9.0","v2.8.1","v2.8.0","v2.8.0-rc.1","v2.8.0-rc.0","v2.7.0-rc.0","v2.6.0-rc.0","v2.5.0-rc.1","v2.5.0-rc.0","v2.4.0","v2.4.0-rc.0","v2.3.0-rc.0","v2.2.0-rc.0","v2.1.0-rc.0","v2.0.0","v2.0.0-rc.0","v1.5.0","v1.5.0-rc.2","v1.5.0-rc.1","v1.5.0-rc.0","v1.4.0","v1.4.0-rc.0","v1.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21728.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}