Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
HIGH 7.5 Go

Grafana Tempo has Inadequate Encryption Strength

GHSA-ffqx-q65f-36jf · CVE-2026-28377 · GO-2026-5359

Published · Modified

Description

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.

Grafana thanks william_goodfellow for reporting this vulnerability.

Ready to move

Start Securing

Free, no credit card | First findings in minutes