CVE-2026-40894
MEDIUMDescription
OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| opentelemetry | opentelemetry |
| opentelemetry | opentelemetry.api |
| opentelemetry | opentelemetry.extensions.propagators |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-40894? +
How severe is CVE-2026-40894? +
What products are affected by CVE-2026-40894? +
How do I check if I'm vulnerable to CVE-2026-40894? +
Related Vulnerabilities
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads …
Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. …
A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure …
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie …
Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, …
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Versions Affected: before 2.5.9 before 3.0.0-M3 Description: The …