CVE-2026-42191Disclosure(opentelemetry / opentelemetry.exporter.opentelemetryprotocol)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol) exporter implementation. From 1.8.0 to 1.15.2, the OTLP disk retry feature in OpenTelemetry.Exporter.OpenTelemetryProtocol silently fell back to Path.GetTempPath() when OTEL_DOTNET_EXPERIMENTAL_OTLP_RETRY=disk was set but OTEL_DOTNET_EXPERIMENTAL_OTLP_DISK_RETRY_DIRECTORY_PATH was not configured. The exporter stored and loaded *.blob files under fixed, signal-named subdirectories (traces, metrics, logs) beneath that shared temporary root path. On multi-user systems where the temporary directory is accessible to other local accounts, this allows an attacker to write crafted *.blob files, read *.blob files written by the application between export failures, or deposit numerous or oversized blob files, degrading retry-loop performance or consuming disk space. This vulnerability is fixed in 1.15.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-379

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opentelemetry.exporter.opentelemetryprotocol

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-12)
  • 3 total mentions across 2 days

Affected systems

Products
opentelemetry.exporter.opentelemetryprotocol

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-01: 1Mentions · 2026-05-12: 2Technical Details · 2026-05-01: 1Technical Details · 2026-05-12: 105-0105-12
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-011
General1
2026-05-122
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42191 OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol) exporter implementation. From 1.8.0 to 1.15.2, the OTLP disk retry feature in OpenTe… https://www.cve.org/CVERecord?id=CVE-2026-42191 ----- Traducción: CVE-2026-42191 Ope… http://infoflow.cloud`

    Post summary

    The post announces a new CVE (CVE‑2026‑42191) for OpenTelemetry, providing the affected component and version range, but offers no PoC, exploit, patch, or active exploitation details.

    0000033
    77 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42191 OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol) exporter implementation. From 1.8.0 to 1.15.2, the OTLP disk retry feature in OpenTe… https://www.cve.org/CVERecord?id=CVE-2026-42191

    Post summary

    The text announces CVE-2026-42191 affecting OpenTelemetry’s OTLP exporter between versions 1.8.0 and 1.15.2, but provides no further details on exploitation or mitigation.

    00000143
    57.5K followersView on X
  • DailyCVE@dailycve
    General

    🟠 OpenTelemetry NET, Path Traversal/Local Privilege Escalation, #CVE-2026-42191 (Moderate) https://dailycve.com/opentelemetry-net-path-traversal-local-privilege-escalation-cve-2026-42191-moderate/

    Post summary

    Tweet alerts about a moderate‑severity Path Traversal/Local Privilege Escalation bug in OpenTelemetry NET, but provides no evidence of exploitation, PoC, tool, or patch.

    0000029
    192 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopentelemetryopentelemetry.exporter.opentelemetryprotocol-.net-

Explore more