CVE-2026-40891Disclosure(opentelemetry / opentelemetry)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch opentelemetry opentelemetry systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC using the OpenTelemetry Protocol (OTLP), the exporter may parse a server-provided grpc-status-details-bin trailer during retry handling. Prior to the fix, a malformed trailer could encode an extremely large length-delimited protobuf field which was used directly for allocation, allowing excessive memory allocation and potential denial of service (DoS). This vulnerability is fixed in 1.15.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-789

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opentelemetry

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-23); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
opentelemetry

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-23: 1Mentions · 2026-04-28: 1Mentions · 2026-05-31: 1Patch / Workaround · 2026-05-31: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-31: 104-2304-2805-31
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-04-281
Disclosure1
2026-05-311
Patch1
Full discourse3 posts
  • yottajunaid@yottajunaid
    Patch

    @BleepinComputer In order to get beyond MFA and steal session cookies, the exploit combines CVE-2026-40891 with a second flaw (CVE-2026-40892). This enables hackers to take over active VPN sessions without the need for passwords. Patch 6.2.5 or 6.3.3 right away, and terminate any open sessions.

    Post summary

    The post warns that CVE-2026-40891 and CVE-2026-40892 can be combined to bypass MFA and hijack VPN sessions, urging immediate application of patches 6.2.5 or 6.3.3.

    00011748
    12 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-40891: CVE-2026-40891: Denial of Service via Unbounded Memory Allocation in OpenTelemetry .NET gRPC Trailer Parsing The OpenTelemetry .NET SDK is vulnerable to a Denial of Service (DoS) flaw due to unbounded memory allocation during the deser... https://cvereports.com/reports/CVE-2026-40891

    Post summary

    The text announces CVE‑2026‑40891, outlining a DoS vulnerability in the OpenTelemetry .NET SDK stemming from unbounded memory allocation during gRPC trailer parsing, but it provides no PoC, exploit, or remediation details.

    0000024
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40891 OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC using the OpenTelemetry Protocol (OTLP), the ex… https://www.cve.org/CVERecord?id=CVE-2026-40891

    Post summary

    The post announces a new CVE (CVE‑2026‑40891) affecting OpenTelemetry dotnet versions 1.13.1 through 1.15.1 when exporting telemetry over gRPC using OTLP, but provides no evidence of exploits or mitigations.

    00000103
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopentelemetryopentelemetry-.net-

Explore more