Denial of Service Vulnerability in OpenTelemetry Dotnet by OpenTelemetry
CVE-2026-40894

5.3MEDIUM

What is CVE-2026-40894?

A vulnerability in the OpenTelemetry tracking system for .NET applications has been identified, affecting specific versions of the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages. The flaw stems from improper handling of processing code related to baggage, B3, and Jaeger, which can lead to excessive memory allocation during parsing operations. This may result in a potential denial of service (DoS) for applications utilizing these packages. Users are encouraged to upgrade to version 1.15.3 or later to mitigate this issue and ensure optimal application performance.

Affected Version(s)

opentelemetry-dotnet >= 0.5.0-beta.2, < 1.15.3

OpenTelemetry.Api >= 0.5.0-beta.2, < 1.15.3

OpenTelemetry.Extensions.Propagators >= 1.3.1, < 1.15.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.