Denial of Service Vulnerability in OpenTelemetry.Api by OpenTelemetry
CVE-2025-27513

7.5HIGH

Key Information:

Vendor
CVE Published:
5 March 2025

What is CVE-2025-27513?

A vulnerability in the OpenTelemetry.Api package versions 1.10.0 to 1.11.1 can lead to a Denial of Service (DoS) condition when applications receive specific tracestate and traceparent headers. Even applications not actively utilizing trace context propagation may experience severe side effects, such as increased CPU usage and resource depletion. This issue predominantly affects web-accessible applications and backend services processing HTTP requests with such headers, resulting in significant latency, degradation in performance, or system downtime. The vulnerability has been resolved in version 1.11.2.

Affected Version(s)

opentelemetry-dotnet >= 1.10.0-beta.1, < 1.11.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.