PT-2026-37115 · Unknown · Opentelemetry.Resources.Azure
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenTelemetry.Resources.Azure versions prior to 1.15.0-beta.2
Description
The
AzureVmMetaDataRequestor() function makes HTTP requests to the Azure VM instance metadata service and reads the response body into memory without a size limit. An attacker who controls the configured endpoint or intercepts traffic via a man-in-the-middle attack can return an arbitrarily large response body. This leads to unbounded heap allocation, causing high transient memory pressure, garbage-collection stalls, or an OutOfMemoryException that terminates the process, resulting in a Denial of Service (DoS).Recommendations
Update to version 1.15.0-beta.2 or later.
Disable the Azure VM resource detector.
Use network-level controls such as firewall rules, mTLS, or a service mesh to prevent man-in-the-middle attacks on the Azure VM instance metadata endpoint.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opentelemetry.Resources.Azure