CVE-2026-41484General(opentelemetry / opentelemetry.exporter.onecollector)

LOWCVSS 5.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In versions 1.15.0 and earlier, when a request to the configured back-end or collector results in an unsuccessful HTTP 4xx or 5xx response, the HttpJsonPostTransport class reads the entire response body into memory with no upper bound on the number of bytes consumed in order to include the error response in operator logs. An attacker who controls the configured endpoint, or who can intercept traffic to it via a man-in-the-middle attack, can return an arbitrarily large response body. This causes unbounded heap allocation in the consuming process, leading to high transient memory pressure, garbage-collection stalls, or an OutOfMemoryException that terminates the process. As a workaround, use network-level controls such as firewall rules, mTLS, or a service mesh to prevent man-in-the-middle attacks on the configured back-end or collector endpoint. This issue is fixed in version 1.15.1, which limits the number of bytes read from the response body in an error condition to 4 MiB.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opentelemetry.exporter.onecollector

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
opentelemetry.exporter.onecollector

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-07: 3Technical Details · 2026-05-07: 105-07
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-41484 OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In versions 1.15.0 and earlier, when a request to th… https://www.cve.org/CVERecord?id=CVE-2026-41484 ----- Traducción: CVE-2026-41484 Ope… http://infoflow.cloud`

    Post summary

    The text merely references CVE-2026-41484 with minimal description, lacking actionable or detailed vulnerability information.

    0000031
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41484 OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In versions 1.15.0 and earlier, when a request to th… https://www.cve.org/CVERecord?id=CVE-2026-41484

    Post summary

    The text briefly references CVE-2026-41484 and links to its official record, but provides no detailed information on exploitation, patches, or technical aspects.

    00000125
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41484 Unbounded Memory Consumption in OpenTelemetry.Exporter.OneCollector Vers... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41484 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A CVE‑2026‑41484 vulnerability notification is shared, detailing an unbounded memory consumption issue in OpenTelemetry, but no PoC, exploit, active use, or patch information is included.

    0000049
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopentelemetryopentelemetry.exporter.onecollector-.net-

Explore more