
S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern) CVE: CVE-2026-28377 PT-Identifier: PT-2026-26315 Vendor: Grafana Product: Tempo CVSS: 7.5 Credits: n/a Description: A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-28377 • https://grafana.com/security/security-advisories/cve-2026-28377
Post summary
The text announces a disclosure of CVE-2026-28377, detailing that Grafana Tempo exposes S3 SSE‑C encryption keys via the /status/config endpoint, with a CVSS score of 7.5.




