HIGH 7.5 Go

Grafana Tempo has Inadequate Encryption Strength

GHSA-ffqx-q65f-36jf · CVE-2026-28377 · GO-2026-5359

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.

Grafana thanks william_goodfellow for reporting this vulnerability.

Ready to move

Start Securing

Free, no credit card | First findings in minutes