CVE-2026-41483General(opentelemetry / opentelemetry.resources.azure)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequestor class makes HTTP requests to the Azure VM instance metadata service and reads the response body into memory without any size limit. An attacker who controls the configured endpoint, or who can intercept traffic to it via a man-in-the-middle attack, can return an arbitrarily large response body. This causes unbounded heap allocation in the consuming process, leading to high transient memory pressure, garbage-collection stalls, or an OutOfMemoryException that terminates the process. As a workaround, disable the Azure VM resource detector or use network-level controls such as firewall rules, mTLS, or a service mesh to prevent man-in-the-middle attacks on the Azure VM instance metadata endpoint. This issue is fixed in version 1.15.1-beta.1, which streams responses rather than buffering them entirely in memory and ignores responses larger than 4 MiB.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opentelemetry.resources.azure

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-07); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
opentelemetry.resources.azure

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-07: 3Mentions · 2026-05-17: 1Technical Details · 2026-05-07: 205-0705-17
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-073
Disclosure1General2
2026-05-171
General1
Full discourse4 posts
  • Israel@f1tym1
    General

    CVE-2026-41483 | open-telemetry opentelemetry-dotnet-contrib up to 1.15.0-beta.1 Response Body AzureVmMetaDataRequestor allocation of resources (GHSA-vc24-j8c5-2vw4) https://ift.tt/Y7Top43 A vulnerability, which was classified as problematic, has been found in open-telemetry o…

    Post summary

    The post flags CVE‑2026‑41483 in open‑telemetry opentelemetry‑dotnet‑contrib and links to a GHSA advisory, but provides no technical details, PoC, exploit code, or mitigation information.

    0100071
    974 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-41483 http://OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequestor class makes HT… https://www.cve.org/CVERecord?id=CVE-2026-41483 ----- Traducción: CVE-2026-41483 … http://infoflow.cloud`

    Post summary

    The tweet documents the announcement of CVE‑2026‑41483, noting its impact on the OpenTelemetry .NET resource detector for Azure environments, but offers no PoC, exploit, or patch details.

    0000029
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41483 http://OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequestor class makes HT… https://www.cve.org/CVERecord?id=CVE-2026-41483

    Post summary

    The text announces CVE‑2026‑41483 affecting the OpenTelemetry.Azure resource detector by referencing a class but provides no PoC, exploit, or mitigation details.

    00000127
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41483 Unbounded Memory Allocation in http://OpenTelemetry.Resources.Azure Versions 1.15.0-beta.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41483

    Post summary

    The text simply announces CVE-2026-41483 as an unbounded memory allocation issue in OpenTelemetry.Resources.Azure v1.15.0-beta.1, without providing PoC, exploitation, patch, or remediation details.

    0000054
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopentelemetryopentelemetry.resources.azure-.net-

Explore more