Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 76%

CVE-2026-42348: CWE-789: Memory Allocation with Excessive Size Value in open-telemetry opentelemetry-dotnet-contrib

0
Medium
VulnerabilityCVE-2026-42348cvecve-2026-42348cwe-789
Published: 05/12/2026 (05/12/2026, 18:01:41 UTC)
Source: CVE Database V5
Vendor/Project: open-telemetry
Product: opentelemetry-dotnet-contrib

Description

CVE-2026-42348 is a medium severity vulnerability in the OpenTelemetry. OpAmp. Client component of opentelemetry-dotnet-contrib versions prior to 0.2.0-alpha.1. The issue involves the client allocating an unbounded buffer to read HTTP responses from the OpAMP server without an upper size limit. This can lead to memory exhaustion if the server is attacker-controlled or if a network attacker can intercept and send a very large response body. The vulnerability is fixed starting from version 0.2.

CVSS v3.1

Score 5.9medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

GitHub Actionsmore threats →ai
open-telemetry/opentelemetry-dotnet-contrib
pkg:github/open-telemetry/opentelemetry-dotnet-contrib
Affected versions
<0.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/20/2026, 19:08:19 UTC

Technical Analysis

The OpenTelemetry.OpAmp.Client prior to version 0.2.0-alpha.1 does not impose an upper bound on the size of the buffer allocated to read HTTP responses from the OpAMP server. This lack of size limitation allows an attacker controlling the OpAMP server or performing a man-in-the-middle attack to cause the client to allocate excessive memory, potentially exhausting system resources. This vulnerability is classified under CWE-789 (Memory Allocation with Excessive Size Value). The issue has a CVSS v3.1 base score of 5.9, reflecting a network attack vector with high complexity and no privileges required, resulting in availability impact only. The vulnerability is resolved in version 0.2.0-alpha.1 of the opentelemetry-dotnet-contrib package.

Potential Impact

An attacker capable of controlling the OpAMP server or intercepting the network traffic can cause the vulnerable client to allocate an unbounded amount of memory by sending an extremely large HTTP response body. This can lead to memory exhaustion and potentially cause the consuming application to crash or become unresponsive, impacting availability. There is no impact on confidentiality or integrity according to the CVSS vector.

Mitigation Recommendations

This vulnerability is fixed in opentelemetry-dotnet-contrib version 0.2.0-alpha.1. Users should upgrade to this version or later to remediate the issue. Since no official patch or temporary fix is indicated beyond upgrading, applying this update is the recommended action. There is no indication that the vulnerability is mitigated by configuration or network controls alone.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-04-26T13:26:14.515Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 6a036fcccbff5d86100cc53c

Added to database: 05/12/2026, 18:22:04 UTC

Last enriched: 05/20/2026, 19:08:19 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 97

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses