---
id: CVE-2026-21728
title: >-
  Tempo queries with large limits can cause large memory allocations which can
  impact the availability of the service, depending on its deployment strategy.


  Mitigation can be done by setting max_result_limit in the search config, e.g
summary: >-
  Tempo queries with large limits can cause large memory allocations which can
  impact the availability of the service, depending on its deployment strategy.


  Mitigation can be done by setting max_result_limit in the search config, e.g.
  to …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-770
vendor: grafana
product: tempo
affected:
  - 'tempo >= 1.3.0, < 2.8.4'
  - 'tempo >= 2.9.0, < 2.9.2'
  - 'tempo >= 2.10.0, < 2.10.2'
patched:
  - tempo 2.10.2
published: '2026-04-24'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T13:18:44.397'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-21728'
references:
  - url: 'https://grafana.com/security/security-advisories/cve-2026-21728'
    label: security@grafana.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:21769'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22347'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22423'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:23345'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24503'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-21728'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2461395'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21728.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-21728'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-21728'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-04-24T11:29:58.649315Z'
epss: 0.00637
epssPercentile: 0.49156
ingestedAt: '2026-06-29T21:48:47.443Z'
---

## Overview

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.

## Affected

- `tempo >= 1.3.0, < 2.8.4`
- `tempo >= 2.9.0, < 2.9.2`
- `tempo >= 2.10.0, < 2.10.2`

## Remediation

Upgrade past the affected range:

- `tempo 2.10.2`

## Vendor advisories

- **RHSA-2026:22423** · Red Hat · fixed in: Multicluster Global Hub 1.3.4 · released 2026-06-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:22423)
- **RHSA-2026:22347** · Red Hat · fixed in: Multicluster Global Hub 1.4.5 · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22347)
- **RHSA-2026:23345** · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23345)
- **RHSA-2026:24503** · Red Hat · fixed in: Multicluster Global Hub 1.7.0 · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24503)
- **RHSA-2026:21769** · Red Hat · fixed in: Red Hat multicluster global hub 1.5.3 · released 2026-05-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:21769)
- **Red Hat VEX** · Important · affected: Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, Red Hat Ceph Storage 9, Red Hat OpenShift distributed tracing 3 · no fix planned: Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, Red Hat Ceph Storage 9, Red Hat OpenShift distributed tracing 3 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21728.json)
