A AegiFlow
HIGHCVSS 7.5EPSS 0.2%

CVE-2026-28377

Grafana Tempo has Inadequate Encryption Strength

Published
2026-03-27
Modified
2026-07-21
EPSS percentile
5%
Aliases
GHSA-ffqx-q65f-36jf
Sources
github-advisory

Summary

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/grafana/tempo2.10.3

Remediation: Upgrade to 2.10.3 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.