VDB

TNCVE-2026-28377

TNCVE-2026-28377 PUBLISHED

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.

Timeline

  • Mar 26, 2026 CVE Published

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›