CVE-2026-40891
MEDIUMOpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
Title source: cnaDescription
OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC using the OpenTelemetry Protocol (OTLP), the exporter may parse a server-provided grpc-status-details-bin trailer during retry handling. Prior to the fix, a malformed trailer could encode an extremely large length-delimited protobuf field which was used directly for allocation, allowing excessive memory allocation and potential denial of service (DoS). This vulnerability is fixed in 1.15.2.
Scores
CVSS v3
5.3
EPSS
0.0002
EPSS Percentile
4.5%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-789
Status
published
Products (4)
nuget/OpenTelemetry.Exporter.OpenTelemetryProtocol
1.13.1 - 1.15.3NuGet
open-telemetry/opentelemetry-dotnet
>= 1.13.1, < 1.15.3
open-telemetry/OpenTelemetry.Exporter.OpenTelemetryProtocol
>= 1.13.1, < 1.15.3
opentelemetry/opentelemetry
1.13.1 - 1.15.3
Published
Apr 23, 2026
Tracked Since
Apr 23, 2026