CVE-2026-40894
In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet…
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-789
- Affected
- opentelemetry/opentelemetry · opentelemetry/opentelemetry.api · opentelemetry/opentelemetry.extensions.propagators
- Source
- security-advisories@github.com
References
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/1048Issue Tracking, Patch
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/3244Issue Tracking, Patch
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/3309Issue Tracking, Patch
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/533Issue Tracking, Patch
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/7061Issue Tracking, Patch
- https://github.com/open-telemetry/opentelemetry-dotnet/security/advisories/GHSA-g94r-2vxg-569jMitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.