CVE-2026-48504Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unnecessary CPU work and short-lived heap allocations while parsing entries later discarded by the SDK's baggage storage limits. Services that accept untrusted inbound propagation headers may experience increased per-request resource usage when processing oversized baggage headers. This issue is fixed in version 0.32.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-25: 1Technical Details · 2026-06-25: 106-25
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve
    Disclosure

    🟠 OpenTelemetry Rust SDK, Unbounded Memory Allocation in W3C Baggage Propagation, #CVE-2026-48504 (Medium) -DC-Jun2026-645 https://dailycve.com/opentelemetry-rust-sdk-unbounded-memory-allocation-in-w3c-baggage-propagation-cve-2026-48504-medium-dc-jun2026-645/

    Post summary

    The post announces CVE‑2026‑48504, an unbounded memory allocation issue in OpenTelemetry Rust SDK’s W3C Baggage Propagation, rated Medium, with no claims about PoC, exploits, patches, or active exploitation.

    0000035
    216 followersView on X

Explore more