CVE-2026-21728
גבוהה 7.5
תיאור (מקור, אנגלית)
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-26/9/2026
- CWE
- CWE-400, CWE-770
מוצרים מושפעים
grafana: tempo
קישורים
- https://grafana.com/security/security-advisories/cve-2026-21728 Broken Link
- https://access.redhat.com/errata/RHSA-2026:21769
- https://access.redhat.com/errata/RHSA-2026:22347
- https://access.redhat.com/errata/RHSA-2026:22423
- https://access.redhat.com/errata/RHSA-2026:23345
- https://access.redhat.com/errata/RHSA-2026:24503
- https://access.redhat.com/security/cve/CVE-2026-21728
- https://bugzilla.redhat.com/show_bug.cgi?id=2461395
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21728.json