CVE-2025-27513

HIGH

OpenTelemetry.Api 1.10.0-1.11.1 - Denial of Service via Tracestate Header Processing

Title source: llm
STIX 2.1

Description

OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTelemetry.Api package 1.10.0 to 1.11.1 could cause a Denial of Service (DoS) when a tracestate and traceparent header is received. Even if an application does not explicitly use trace context propagation, receiving these headers can still trigger high CPU usage. This issue impacts any application accessible over the web or backend services that process HTTP requests containing a tracestate header. Application may experience excessive resource consumption, leading to increased latency, degraded performance, or downtime. This vulnerability is fixed in 1.11.2.

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (2)
nuget/OpenTelemetry.Api 1.11.0 - 1.11.2NuGet
open-telemetry/opentelemetry-dotnet >= 1.10.0-beta.1, < 1.11.2
Published Mar 05, 2025
Tracked Since Feb 18, 2026