Multiple vulnerabilities in Grafana Tempo allow a remote, anonymous attacker to perform a Denial of Service attack. The CVSS Base Score for these issues is 7.5 (High). Affected versions include Tempo versions prior to 2.8.8, 2.10.2, 2.8.4, and 2.9.2, and a mitigation is available.
[WID-SEC-2026-2342] Grafana Tempo: Mehrere Schwachstellen ermöglichen Denial of Service CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 14.07.2026 Stand 15.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Produktbeschreibung Grafana Tempo ist ein hochskalierbares, verteiltes Tracing-Backend. Produkte 14.07.2026 Grafana Tempo <2.8.8 Grafana Tempo <2.10.2 Grafana Tempo <2.8.4 Grafana Tempo <2.9.2 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Grafana Tempo ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben