GHSA-ffqx-q65f-36jfHighCVSS 7.5

Grafana Tempo has Inadequate Encryption Strength

Published
March 27, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (1)

📋 Description

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.

🎯 Affected products1

  • go/github.com/grafana/tempo:< 2.10.3

🔗 References (5)