๐Ÿ” CVE Alert

CVE-2026-41484

MEDIUM 5.3

OpenTelemetry.Exporter.OneCollector vulnerable to denial of service via unbounded HTTP error response body

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In versions 1.15.0 and earlier, when a request to the configured back-end or collector results in an unsuccessful HTTP 4xx or 5xx response, the HttpJsonPostTransport class reads the entire response body into memory with no upper bound on the number of bytes consumed in order to include the error response in operator logs. An attacker who controls the configured endpoint, or who can intercept traffic to it via a man-in-the-middle attack, can return an arbitrarily large response body. This causes unbounded heap allocation in the consuming process, leading to high transient memory pressure, garbage-collection stalls, or an OutOfMemoryException that terminates the process. As a workaround, use network-level controls such as firewall rules, mTLS, or a service mesh to prevent man-in-the-middle attacks on the configured back-end or collector endpoint. This issue is fixed in version 1.15.1, which limits the number of bytes read from the response body in an error condition to 4 MiB.

CWE CWE-770
Vendor open-telemetry
Product opentelemetry-dotnet-contrib
Published May 6, 2026
Stay Ahead of the Next One

Get instant alerts for open-telemetry opentelemetry-dotnet-contrib

Be the first to know when new medium vulnerabilities affecting open-telemetry opentelemetry-dotnet-contrib are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

open-telemetry / opentelemetry-dotnet-contrib
<= 1.15.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisories/GHSA-55m9-299j-53c7 github.com: https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4117