CVE-2025-27513
HIGHOpenTelemetry.Api 1.10.0-1.11.1 - Denial of Service via Tracestate Header Processing
Title source: llmDescription
OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTelemetry.Api package 1.10.0 to 1.11.1 could cause a Denial of Service (DoS) when a tracestate and traceparent header is received. Even if an application does not explicitly use trace context propagation, receiving these headers can still trigger high CPU usage. This issue impacts any application accessible over the web or backend services that process HTTP requests containing a tracestate header. Application may experience excessive resource consumption, leading to increased latency, degraded performance, or downtime. This vulnerability is fixed in 1.11.2.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/open-telemetry/opentelemetry-dotnet/security/advisories/GHSA-8785-wc3w-h8q6
Scores
CVSS v3
7.5
EPSS
0.0005
EPSS Percentile
16.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (2)
nuget/OpenTelemetry.Api
1.11.0 - 1.11.2NuGet
open-telemetry/opentelemetry-dotnet
>= 1.10.0-beta.1, < 1.11.2
Published
Mar 05, 2025
Tracked Since
Feb 18, 2026