Denial of Service Vulnerability in OpenTelemetry Dotnet by OpenTelemetry
CVE-2026-40894
5.3MEDIUM
What is CVE-2026-40894?
A vulnerability in the OpenTelemetry tracking system for .NET applications has been identified, affecting specific versions of the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages. The flaw stems from improper handling of processing code related to baggage, B3, and Jaeger, which can lead to excessive memory allocation during parsing operations. This may result in a potential denial of service (DoS) for applications utilizing these packages. Users are encouraged to upgrade to version 1.15.3 or later to mitigate this issue and ensure optimal application performance.
Affected Version(s)
opentelemetry-dotnet >= 0.5.0-beta.2, < 1.15.3
OpenTelemetry.Api >= 0.5.0-beta.2, < 1.15.3
OpenTelemetry.Extensions.Propagators >= 1.3.1, < 1.15.3
