CVE-2026-40894

MEDIUM

OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers

Title source: cna
STIX 2.1

Description

OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.

Scores

CVSS v3 5.3
EPSS 0.0003
EPSS Percentile 7.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-789
Status published
Products (8)
nuget/OpenTelemetry.Api 0.5.0-beta.2 - 1.15.3NuGet
nuget/OpenTelemetry.Extensions.Propagators 1.3.1 - 1.15.3NuGet
open-telemetry/opentelemetry-dotnet >= 0.5.0-beta.2, < 1.15.3
open-telemetry/OpenTelemetry.Api >= 0.5.0-beta.2, < 1.15.3
open-telemetry/OpenTelemetry.Extensions.Propagators >= 1.3.1, < 1.15.3
opentelemetry/opentelemetry 0.5.0 - 1.15.3
opentelemetry/opentelemetry.api 0.5.0 - 1.15.3
opentelemetry/opentelemetry.extensions.propagators 1.3.0 - 1.15.3
Published Apr 23, 2026
Tracked Since Apr 24, 2026