VDB
CVE-2026-40894
CVE-2026-40894
PUBLISHED
CVSS 5.300000190734863 MEDIUM
OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.
EPSS 0.03% · 8.5th percentile
Risk Scores
CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.03%
8.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| open-telemetry | opentelemetry-dotnet | >= 0.5.0-beta.2, < 1.15.3 |
| NuGet | OpenTelemetry.Api | 0.5.0-beta.2 |
| open-telemetry | OpenTelemetry.Extensions.Propagators | >= 1.3.1, < 1.15.3 |
| open-telemetry | OpenTelemetry.Api | >= 0.5.0-beta.2, < 1.15.3 |
| NuGet | OpenTelemetry.Extensions.Propagators | 1.3.1 |
Timeline
- Apr 23, 2026 CVE Published
- Apr 24, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score
References
- https://github.com/open-telemetry/opentelemetry-dotnet/security/advisories/GHSA-g94r-2vxg-569j url
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/1048 url
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/3244 url
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/3309 url
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/533 url
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/7061 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-40894 advisory
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/3533 url
- https://github.com/open-telemetry/opentelemetry-dotnet package
- https://github.com/open-telemetry/opentelemetry-dotnet/releases/tag/core-1.15.3 url