Feed/CVE-2026-28377
CVE-2026-28377HIGHCVSS 7.5

Grafana Tempo has Inadequate Encryption Strength

Published Mar 27, 2026·Updated Jul 21, 2026

NVD Description

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.

Affected Packages (1)

github.com/grafana/tempoGO
Fixed in 2.10.3

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free