CVE-2026-40182

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/04/2026
Last modified:
29/04/2026

Description

OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry to a back-end/collector over gRPC or HTTP using OpenTelemetry Protocol format (OTLP), if the request results in a unsuccessful request (i.e. HTTP 4xx or 5xx), the response is read into memory with no upper-bound on the number of bytes consumed. This could cause memory exhaustion in the consuming application if the configured back-end/collector endpoint is attacker-controlled (or a network attacker can MitM the connection) and an extremely large body is returned by the response. This vulnerability is fixed in 1.15.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:.net:*:* 1.13.1 (including) 1.15.2 (excluding)