CVE-2026-40894
CVE-2026-40894 is a medium-severity vulnerability in Opentelemetry with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-789.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 0% (38th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-25269
- Weakness: CWE-789
- Affected product: Opentelemetry
- Published:
- Last modified:
Description
OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.
Frequently asked questions
- What is CVE-2026-40894?
- OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.
- How severe is CVE-2026-40894?
- CVE-2026-40894 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2026-40894 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (38th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-40894?
- CVE-2026-40894 primarily affects Opentelemetry. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-40894?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-40894 have an EU (EUVD) identifier?
- Yes. CVE-2026-40894 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-25269.
- When was CVE-2026-40894 published?
- CVE-2026-40894 was published on 2026-04-23 and last updated on 2026-06-17.
References
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/1048
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/3244
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/3309
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/533
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/7061
- https://github.com/open-telemetry/opentelemetry-dotnet/security/advisories/GHSA-g94r-2vxg-569j
Affected products (3)
- cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:.net:*:*
- cpe:2.3:a:opentelemetry:opentelemetry.api:*:*:*:*:*:.net:*:*
- cpe:2.3:a:opentelemetry:opentelemetry.extensions.propagators:*:*:*:*:*:*:*:*
More vulnerabilities in Opentelemetry
- CVE-2026-29181 — High (CVSS 7.5): OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header…
- CVE-2023-47108 — High (CVSS 7.5): OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and…
- CVE-2023-45142 — High (CVSS 7.5): OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box…
- CVE-2023-43810 — High (CVSS 7.5): OpenTelemetry, also known as OTel for short, is a vendor-neutral open-source Observability framework for instrumenting,…
- CVE-2026-39883 — High (CVSS 7.0): OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed…
- CVE-2026-24051 — High (CVSS 7.0): OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is…
All CVEs affecting Opentelemetry →
Other CWE-789 vulnerabilities
- CVE-2021-34869 — High (CVSS 8.8): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop…
- CVE-2021-34868 — High (CVSS 8.8): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop…
- CVE-2026-69219 — High (CVSS 8.7): The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.…
- CVE-2026-58067 — High (CVSS 8.7): A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause…
- CVE-2026-14682 — High (CVSS 8.7): In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This…
- CVE-2026-12852 — High (CVSS 8.7): In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.