Back to CVE List

CVE-2026-40891

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.3 / 10
Vector String
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Description

OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC using the OpenTelemetry Protocol (OTLP), the exporter may parse a server-provided grpc-status-details-bin trailer during retry handling. Prior to the fix, a malformed trailer could encode an extremely large length-delimited protobuf field which was used directly for allocation, allowing excessive memory allocation and potential denial of service (DoS). This vulnerability is fixed in 1.15.2.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-789
Source
NVD
Vendor
open-telemetry
Product
opentelemetry-dotnet, OpenTelemetry.Exporter.OpenTelemetryProtocol

External References

Discussion (0)

Add Comment

No comments yet. Be the first!