CVE-2026-40891

MEDIUM

OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling

Title source: cna
STIX 2.1

Description

OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC using the OpenTelemetry Protocol (OTLP), the exporter may parse a server-provided grpc-status-details-bin trailer during retry handling. Prior to the fix, a malformed trailer could encode an extremely large length-delimited protobuf field which was used directly for allocation, allowing excessive memory allocation and potential denial of service (DoS). This vulnerability is fixed in 1.15.2.

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 4.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-789
Status published
Products (4)
nuget/OpenTelemetry.Exporter.OpenTelemetryProtocol 1.13.1 - 1.15.3NuGet
open-telemetry/opentelemetry-dotnet >= 1.13.1, < 1.15.3
open-telemetry/OpenTelemetry.Exporter.OpenTelemetryProtocol >= 1.13.1, < 1.15.3
opentelemetry/opentelemetry 1.13.1 - 1.15.3
Published Apr 23, 2026
Tracked Since Apr 23, 2026