<Vulnerability name="CVE-2026-21728">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-04-24T08:00:47</PublicDate>
    <Bugzilla id="2461395" url="https://bugzilla.redhat.com/show_bug.cgi?id=2461395" xml:lang="en:us">
grafana/tempo: Tempo: Denial of Service via large queries
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-770</CWE>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Tempo. A remote attacker can exploit this vulnerability by sending large queries to the Tempo service. This can lead to excessive memory allocations, potentially causing a Denial of Service (DoS) by impacting the availability of the service.
    </Details>
    <PackageState cpe="cpe:/a:redhat:logging:6">
        <ProductName>Logging Subsystem for Red Hat OpenShift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-logging/lokistack-gateway-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:multicluster_globalhub">
        <ProductName>Multicluster Global Hub</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>multicluster-globalhub/multicluster-globalhub-grafana-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:multicluster_globalhub">
        <ProductName>Multicluster Global Hub</ProductName>
        <FixState>Affected</FixState>
        <PackageName>multicluster-globalhub/multicluster-globalhub-grafana-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhacm2/acm-grafana-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:5">
        <ProductName>Red Hat Ceph Storage 5</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhceph/rhceph-5-dashboard-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:6">
        <ProductName>Red Hat Ceph Storage 6</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhceph/rhceph-6-dashboard-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:9">
        <ProductName>Red Hat Ceph Storage 9</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhceph/grafana-rhel10</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Affected</FixState>
        <PackageName>grafana</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Affected</FixState>
        <PackageName>grafana</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_distributed_tracing:3">
        <ProductName>Red Hat OpenShift distributed tracing 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhosdt/tempo-gateway-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_distributed_tracing:3">
        <ProductName>Red Hat OpenShift distributed tracing 3</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhosdt/tempo-query-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_distributed_tracing:3">
        <ProductName>Red Hat OpenShift distributed tracing 3</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhosdt/tempo-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_distributed_tracing:3">
        <ProductName>Red Hat OpenShift distributed tracing 3</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhosdt/tempo-rhel9-operator</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-21728
https://nvd.nist.gov/vuln/detail/CVE-2026-21728
https://grafana.com/security/security-advisories/cve-2026-21728
    </References>
</Vulnerability>