CVE-2026-41173Disclosure

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0.1.0-alpha.8, OpenTelemetry.Sampler.AWS reads unbounded HTTP response bodies from a configured AWS X-Ray remote sampling endpoint into memory. AWSXRaySamplerClient.DoRequestAsync called HttpClient.SendAsync followed by ReadAsStringAsync(), which materializes the entire HTTP response body into a single in-memory string with no size limit. The sampling endpoint is configurable via AWSXRayRemoteSamplerBuilder.SetEndpoint (default: http://localhost:2000). An attacker who controls the configured endpoint, or who can intercept traffic to it (MitM), can return an arbitrarily large response body. This causes unbounded heap allocation in the consuming process, leading to high transient memory pressure, garbage-collection stalls, or an OutOfMemoryException that terminates the process. This vulnerability is fixed in 0.1.0-alpha.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-23); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-28: 104-2304-2404-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-41173: CVE-2026-41173: Denial of Service in OpenTelemetry .NET SDK via Unbounded HTTP Allocation The OpenTelemetry .NET SDK AWS extensions contain a Denial of Service (DoS) vulnerability due to unbounded memory allocation. The SDK fails to en... https://cvereports.com/reports/CVE-2026-41173

    Post summary

    The post announces a DoS vulnerability in OpenTelemetry .NET SDK caused by unbounded HTTP memory allocation, providing only basic technical details and no evidence of exploitation or mitigation.

    0000027
    36 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OpenTelemetry (#CVE-2026-41173): Unbounded HTTP Response Body Read Leading to Denial of Service (Critical) https://dailycve.com/opentelemetry-cve-2026-41173-unbounded-http-response-body-read-leading-to-denial-of-service-critical/

    Post summary

    A new CVE‑2026‑41173 in OpenTelemetry has been disclosed, outlining an unbounded HTTP response body read that can cause a denial-of-service.

    0000049
    183 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41173 The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0.1.0-alpha.8, http://OpenTelemetry.Sampler.AWS reads … https://www.cve.org/CVERecord?id=CVE-2026-41173

    Post summary

    The entry reports a vulnerability in AWS X-Ray Remote Sampler files that existed before version 0.1.0-alpha.8, but provides no additional technical or mitigation details.

    00000104
    57.2K followersView on X

Explore more