7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Tempo query limit results in unbounded memory allocation
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18).
References
-
https://grafana.com/security/security-advisories/cve-2026-21728 vendor-advisory
Affected products
- <v2.11.0
Matching in nixpkgs
pkgs.tempo
High volume, minimal dependency trace storage
pkgs.temporal
Microservice orchestration platform which enables developers to build scalable applications without sacrificing productivity or reliability
pkgs.tempora_lgc
Tempora font
pkgs.temporal-cli
Command-line interface for running Temporal Server and interacting with Workflows, Activities, Namespaces, and other parts of Temporal
pkgs.temporal_capi
A Rust implementation of ECMAScript's Temporal API
pkgs.temporal-ui-server
Golang Server for Temporal Web UI
pkgs.gnomeExtensions.tempomate
Effortless time tracking in Jira Tempo timesheets!
pkgs.haskellPackages.temporary
Portable temporary file and directory support
pkgs.python312Packages.tempora
Objects and routines pertaining to date and time
pkgs.python313Packages.tempora
Objects and routines pertaining to date and time
pkgs.python314Packages.tempora
Objects and routines pertaining to date and time
pkgs.tests.haskell.incremental
Portable temporary file and directory support
pkgs.haskellPackages.temporary-rc
Portable temporary file and directory support for Windows and Unix, based on code from Cabal
pkgs.python312Packages.temporalio
Temporal Python SDK
pkgs.python313Packages.temporalio
Temporal Python SDK
pkgs.python314Packages.temporalio
Temporal Python SDK
pkgs.haskellPackages.temporal-media
data types for temporal media
pkgs.haskellPackages.temporary-ospath
Portable temporary file and directory support
-
nixos-unstable -
- nixos-unstable-small 1.3
pkgs.terraform-providers.temporalcloud
None
pkgs.postgresqlPackages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.haskellPackages.temporal-api-protos
None
-
nixos-unstable 2025.10.1.0
- nixpkgs-unstable 2025.10.1.0
- nixos-unstable-small 2025.10.1.0
-
nixos-25.11 2025.10.1.0
- nixos-25.11-small 2025.10.1.0
- nixpkgs-25.11-darwin 2025.10.1.0
pkgs.haskellPackages.temporary-resourcet
Portable temporary files and directories with automatic deletion
pkgs.postgresql14Packages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.postgresql15Packages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.postgresql16Packages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.postgresql17Packages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.postgresql18Packages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.haskellPackages.temporal-music-notation
music notation
pkgs.haskellPackages.temporal-music-notation-demo
generates midi from score notation
Package maintainers
-
@honnip Jung seungwoo <me@honnip.page>
-
@ggPeti Peter Ferenczy <ggpeti@gmail.com>
-
@jpds Jonathan Davies
-
@levigross Levi Gross <levi@levigross.com>
-
@kashw2 Keanu Ashwell <supra4keanu@hotmail.com>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@aaronjheng Aaron Jheng <wentworth@outlook.com>
-
@breakds Break Yang <breakds@gmail.com>
-
@aduh95 Antoine du Hamel <duhamelantoine1995@gmail.com>
-
@Gabriella439 Gabriella Gonzalez <GenuineGabriella@gmail.com>
-
@lf- Jade Lovelace
-
@9999years Rebecca Turner <rbt@fastmail.com>