CVE-2026-41078

OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow sustained memory pressure when the internal pooled-list sizing grows based on a large observed span/tag set and that enlarged size is reused for subsequent allocations. Under high-cardinality or attacker-influenced telemetry input, this can increase memory consumption and potentially cause denial of service. There is no plan to fix this issue as OpenTelemetry.Exporter.Jaeger was deprecated in 2023.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:.net:*:*
cpe:2.3:a:opentelemetry:opentelemetry:1.6.0:alpha1:*:*:*:.net:*:*
cpe:2.3:a:opentelemetry:opentelemetry:1.6.0:beta1:*:*:*:.net:*:*
cpe:2.3:a:opentelemetry:opentelemetry:1.6.0:beta2:*:*:*:.net:*:*
cpe:2.3:a:opentelemetry:opentelemetry:1.6.0:beta3:*:*:*:.net:*:*
cpe:2.3:a:opentelemetry:opentelemetry:1.6.0:rc1:*:*:*:.net:*:*

History

28 Apr 2026, 19:24

Type Values Removed Values Added
References () https://github.com/open-telemetry/opentelemetry-dotnet/security/advisories/GHSA-38h3-2333-qx47 - () https://github.com/open-telemetry/opentelemetry-dotnet/security/advisories/GHSA-38h3-2333-qx47 - Vendor Advisory
CPE cpe:2.3:a:opentelemetry:opentelemetry:1.6.0:beta3:*:*:*:.net:*:*
cpe:2.3:a:opentelemetry:opentelemetry:1.6.0:beta2:*:*:*:.net:*:*
cpe:2.3:a:opentelemetry:opentelemetry:1.6.0:beta1:*:*:*:.net:*:*
cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:.net:*:*
cpe:2.3:a:opentelemetry:opentelemetry:1.6.0:rc1:*:*:*:.net:*:*
cpe:2.3:a:opentelemetry:opentelemetry:1.6.0:alpha1:*:*:*:.net:*:*
First Time Opentelemetry opentelemetry
Opentelemetry

23 Apr 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-23 19:17

Updated : 2026-04-28 19:24


NVD link : CVE-2026-41078

Mitre link : CVE-2026-41078

CVE.ORG link : CVE-2026-41078


JSON object : View

Products Affected

opentelemetry

  • opentelemetry
CWE
CWE-770

Allocation of Resources Without Limits or Throttling