PT-2026-33598 · Unknown · Opentelemetry.Exporter.Jaeger

Kielek

·

Published

2026-04-18

·

Updated

2026-04-23

·

CVE-2026-41078

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenTelemetry.Exporter.Jaeger (affected versions not specified)
Description This issue allows sustained memory pressure when the internal pooled-list sizing grows based on a large observed span or tag set and that enlarged size is reused for subsequent allocations. In environments where telemetry attributes or events can be influenced by untrusted input and limits are increased from defaults, high-cardinality or attacker-influenced telemetry input can increase memory consumption, potentially leading to process instability or denial of service.
Recommendations Use maintained exporters, such as the OpenTelemetry Protocol format (OTLP), instead of the Jaeger exporter.

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41078
GHSA-38H3-2333-QX47

Affected Products

Opentelemetry.Exporter.Jaeger