PT-2026-37115 · Unknown · Opentelemetry.Resources.Azure

·

CVE-2026-41483

·

Published

2026-04-29

·

Updated

2026-05-17

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenTelemetry.Resources.Azure versions prior to 1.15.0-beta.2
Description The AzureVmMetaDataRequestor() function makes HTTP requests to the Azure VM instance metadata service and reads the response body into memory without a size limit. An attacker who controls the configured endpoint or intercepts traffic via a man-in-the-middle attack can return an arbitrarily large response body. This leads to unbounded heap allocation, causing high transient memory pressure, garbage-collection stalls, or an OutOfMemoryException that terminates the process, resulting in a Denial of Service (DoS).
Recommendations Update to version 1.15.0-beta.2 or later. Disable the Azure VM resource detector. Use network-level controls such as firewall rules, mTLS, or a service mesh to prevent man-in-the-middle attacks on the Azure VM instance metadata endpoint.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41483
GHSA-VC24-J8C5-2VW4

Affected Products

Opentelemetry.Resources.Azure