PT-2026-37116 · Unknown · Opentelemetry.Exporter.Onecollector

Smartincostello

·

Published

2026-04-29

·

Updated

2026-05-15

·

CVE-2026-41484

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenTelemetry.Exporter.OneCollector versions prior to 1.15.1
Description When exporting telemetry to a back-end or collector over HTTP, the HttpJsonPostTransport class reads the entire response body into memory without an upper bound if the request results in an unsuccessful HTTP 4xx or 5xx response. An attacker who controls the configured endpoint or intercepts traffic via a man-in-the-middle attack can return an arbitrarily large response body. This leads to unbounded heap allocation, causing high transient memory pressure, garbage-collection stalls, or an OutOfMemoryException that terminates the process, resulting in a denial-of-service condition.
Recommendations Update to version 1.15.1. Use network-level controls such as firewall rules, mTLS, or a service mesh to prevent man-in-the-middle attacks on the configured back-end or collector endpoint.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-41484
GHSA-55M9-299J-53C7

Affected Products

Opentelemetry.Exporter.Onecollector