PT-2026-33598 · Unknown · Opentelemetry.Exporter.Jaeger
Kielek
·
Published
2026-04-18
·
Updated
2026-04-23
·
CVE-2026-41078
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenTelemetry.Exporter.Jaeger (affected versions not specified)
Description
This issue allows sustained memory pressure when the internal pooled-list sizing grows based on a large observed span or tag set and that enlarged size is reused for subsequent allocations. In environments where telemetry attributes or events can be influenced by untrusted input and limits are increased from defaults, high-cardinality or attacker-influenced telemetry input can increase memory consumption, potentially leading to process instability or denial of service.
Recommendations
Use maintained exporters, such as the OpenTelemetry Protocol format (OTLP), instead of the Jaeger exporter.
Fix
DoS
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opentelemetry.Exporter.Jaeger