CVE-2026-42348: CWE-789: Memory Allocation with Excessive Size Value in open-telemetry opentelemetry-dotnet-contrib
CVE-2026-42348 is a medium severity vulnerability in the OpenTelemetry. OpAmp. Client component of opentelemetry-dotnet-contrib versions prior to 0.2.0-alpha.1. The issue involves the client allocating an unbounded buffer to read HTTP responses from the OpAMP server without an upper size limit. This can lead to memory exhaustion if the server is attacker-controlled or if a network attacker can intercept and send a very large response body. The vulnerability is fixed starting from version 0.2.
AI Analysis
Technical Summary
The OpenTelemetry.OpAmp.Client prior to version 0.2.0-alpha.1 does not impose an upper bound on the size of the buffer allocated to read HTTP responses from the OpAMP server. This lack of size limitation allows an attacker controlling the OpAMP server or performing a man-in-the-middle attack to cause the client to allocate excessive memory, potentially exhausting system resources. This vulnerability is classified under CWE-789 (Memory Allocation with Excessive Size Value). The issue has a CVSS v3.1 base score of 5.9, reflecting a network attack vector with high complexity and no privileges required, resulting in availability impact only. The vulnerability is resolved in version 0.2.0-alpha.1 of the opentelemetry-dotnet-contrib package.
Potential Impact
An attacker capable of controlling the OpAMP server or intercepting the network traffic can cause the vulnerable client to allocate an unbounded amount of memory by sending an extremely large HTTP response body. This can lead to memory exhaustion and potentially cause the consuming application to crash or become unresponsive, impacting availability. There is no impact on confidentiality or integrity according to the CVSS vector.
Mitigation Recommendations
This vulnerability is fixed in opentelemetry-dotnet-contrib version 0.2.0-alpha.1. Users should upgrade to this version or later to remediate the issue. Since no official patch or temporary fix is indicated beyond upgrading, applying this update is the recommended action. There is no indication that the vulnerability is mitigated by configuration or network controls alone.
CVE-2026-42348: CWE-789: Memory Allocation with Excessive Size Value in open-telemetry opentelemetry-dotnet-contrib
Description
CVE-2026-42348 is a medium severity vulnerability in the OpenTelemetry. OpAmp. Client component of opentelemetry-dotnet-contrib versions prior to 0.2.0-alpha.1. The issue involves the client allocating an unbounded buffer to read HTTP responses from the OpAMP server without an upper size limit. This can lead to memory exhaustion if the server is attacker-controlled or if a network attacker can intercept and send a very large response body. The vulnerability is fixed starting from version 0.2.
CVSS v3.1
Score 5.9medium
Affected software
pkg:github/open-telemetry/opentelemetry-dotnet-contribRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The OpenTelemetry.OpAmp.Client prior to version 0.2.0-alpha.1 does not impose an upper bound on the size of the buffer allocated to read HTTP responses from the OpAMP server. This lack of size limitation allows an attacker controlling the OpAMP server or performing a man-in-the-middle attack to cause the client to allocate excessive memory, potentially exhausting system resources. This vulnerability is classified under CWE-789 (Memory Allocation with Excessive Size Value). The issue has a CVSS v3.1 base score of 5.9, reflecting a network attack vector with high complexity and no privileges required, resulting in availability impact only. The vulnerability is resolved in version 0.2.0-alpha.1 of the opentelemetry-dotnet-contrib package.
Potential Impact
An attacker capable of controlling the OpAMP server or intercepting the network traffic can cause the vulnerable client to allocate an unbounded amount of memory by sending an extremely large HTTP response body. This can lead to memory exhaustion and potentially cause the consuming application to crash or become unresponsive, impacting availability. There is no impact on confidentiality or integrity according to the CVSS vector.
Mitigation Recommendations
This vulnerability is fixed in opentelemetry-dotnet-contrib version 0.2.0-alpha.1. Users should upgrade to this version or later to remediate the issue. Since no official patch or temporary fix is indicated beyond upgrading, applying this update is the recommended action. There is no indication that the vulnerability is mitigated by configuration or network controls alone.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-26T13:26:14.515Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a036fcccbff5d86100cc53c
Added to database: 05/12/2026, 18:22:04 UTC
Last enriched: 05/20/2026, 19:08:19 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 97
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.