CVE-2026-41310General(opentelemetry / opentelemetry.exporter.zipkin)

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cache accepts unbounded key growth derived from span attributes. In high-cardinality scenarios, a process using Zipkin export for client or producer spans could experience avoidable memory growth under sustained unique remote endpoint values, increasing process memory usage over time and degrading availability. This issue is fixed in version 1.15.3, which introduces a bounded, thread-safe LRU cache for remote endpoints with a fixed maximum size.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opentelemetry.exporter.zipkin

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
opentelemetry.exporter.zipkin

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-07: 3Technical Details · 2026-05-07: 205-07
Signal classification1 categories
General
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-41310 OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cache accepts unbound… https://www.cve.org/CVERecord?id=CVE-2026-41310 ----- Traducción: CVE-2026-41310 Ope… http://infoflow.cloud`

    Post summary

    The tweet merely announces CVE‑2026‑41310 for the OpenTelemetry Zipkin exporter, providing no further technical details, PoC, exploit code, patch information, or evidence of active exploitation.

    0000044
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41310 OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cache accepts unbound… https://www.cve.org/CVERecord?id=CVE-2026-41310

    Post summary

    The post refers to CVE-2026-41310, noting a cache handling issue in the OpenTelemetry Zipkin exporter, but offers no further detail on exploitation, patching, or real‑world attacks.

    00000142
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41310 Unbounded Memory Growth in OpenTelemetry.Exporter.Zipkin Versions 1.15.2 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41310

    Post summary

    The entry references CVE‑2026‑41310, noting an unbounded memory growth issue in OpenTelemetry.Exporter.Zipkin up to version 1.15.2, but offers no details on demos, exploits, or remediation.

    0000050
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopentelemetryopentelemetry.exporter.zipkin-.net-

Explore more