CVE-2026-48504: CWE-770: Allocation of Resources Without Limits or Throttling in open-telemetry opentelemetry-rust
OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unnecessary CPU work and short-lived heap allocations while parsing entries later discarded by the SDK's baggage storage limits. Services that accept untrusted inbound propagation headers may experience increased per-request resource usage when processing oversized baggage headers. This issue is fixed in version 0.32.1.
AI Analysis
Technical Summary
In opentelemetry-rust versions 0.32.0 and earlier, the BaggagePropagator::extract_with_context function in the opentelemetry_sdk did not enforce W3C Baggage size limits prior to parsing inbound baggage headers. As a result, an attacker could send oversized baggage headers that cause unnecessary CPU work and heap allocations during parsing, even though entries exceeding storage limits are later discarded. This resource exhaustion vulnerability could increase per-request resource usage in services accepting untrusted inbound propagation headers. The vulnerability is addressed in version 0.32.1.
Potential Impact
This vulnerability allows an attacker to cause increased CPU and memory usage on affected services by sending large, attacker-controlled baggage headers. While it does not lead to data compromise or denial of service directly, the increased resource consumption could degrade service performance or availability under high load.
Mitigation Recommendations
Upgrade opentelemetry-rust to version 0.32.1 or later, where this issue is fixed. No other mitigations are specified. Patch status is confirmed by the vendor advisory indicating the fix in 0.32.1.
CVE-2026-48504: CWE-770: Allocation of Resources Without Limits or Throttling in open-telemetry opentelemetry-rust
Description
OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unnecessary CPU work and short-lived heap allocations while parsing entries later discarded by the SDK's baggage storage limits. Services that accept untrusted inbound propagation headers may experience increased per-request resource usage when processing oversized baggage headers. This issue is fixed in version 0.32.1.
CVSS v3.1
Score 5.3medium
Affected software
pkg:cargo/github/open-telemetry/opentelemetry-rustRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In opentelemetry-rust versions 0.32.0 and earlier, the BaggagePropagator::extract_with_context function in the opentelemetry_sdk did not enforce W3C Baggage size limits prior to parsing inbound baggage headers. As a result, an attacker could send oversized baggage headers that cause unnecessary CPU work and heap allocations during parsing, even though entries exceeding storage limits are later discarded. This resource exhaustion vulnerability could increase per-request resource usage in services accepting untrusted inbound propagation headers. The vulnerability is addressed in version 0.32.1.
Potential Impact
This vulnerability allows an attacker to cause increased CPU and memory usage on affected services by sending large, attacker-controlled baggage headers. While it does not lead to data compromise or denial of service directly, the increased resource consumption could degrade service performance or availability under high load.
Mitigation Recommendations
Upgrade opentelemetry-rust to version 0.32.1 or later, where this issue is fixed. No other mitigations are specified. Patch status is confirmed by the vendor advisory indicating the fix in 0.32.1.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-21T15:33:08.293Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5b5eac2d1edb114c7fb222
Added to database: 07/18/2026, 11:08:28 UTC
Last enriched: 07/25/2026, 22:51:10 UTC
Last updated: 08/31/2026, 10:52:09 UTC
Views: 43
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.