CVE-2026-28377: S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.
Thanks to williamgoodfellow for reporting this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28377?
CVE-2026-28377 is categorized as a critical vulnerability due to the exposure of sensitive encryption keys.
How do I fix CVE-2026-28377?
To fix CVE-2026-28377, update your Grafana Tempo installation to the latest version where the vulnerability has been patched.
What causes CVE-2026-28377?
CVE-2026-28377 is caused by the S3 SSE-C encryption key being exposed in plaintext through the /status/config endpoint in Grafana Tempo.
Who is affected by CVE-2026-28377?
Any user of Grafana Tempo that accesses the /status/config endpoint may be affected by CVE-2026-28377 if the instance is not properly secured.
What should I do if my system is vulnerable to CVE-2026-28377?
If your system is vulnerable to CVE-2026-28377, you should immediately restrict access to the /status/config endpoint and apply the latest security patches.