github.com/grafana/tempo vulnerabilities
CVEs whose affected-version data names the github.com/grafana/tempo package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-27878Medium· 6.5Grafana Tempo vulnerable to an out-of-memory crash
Grafana Tempo vulnerable to an out-of-memory crash
▾ Sunlitgrafana · github.com/grafana/tempoEPSS 0.41%via OSV
CVE-2026-28377High· 7.5Grafana Tempo has Inadequate Encryption Strength
Grafana Tempo has Inadequate Encryption Strength
▾ Twilightgrafana · github.com/grafana/tempoEPSS 0.16%via OSV