CVE-2026-54285Disclosure(opentelemetry / opentelemetry)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size limits when parsing inbound baggage HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and 180 entries; these limits were only enforced on the outbound (inject()) path, not on the inbound (extract()) path. Parsing oversized baggage causes memory allocation proportional to the header size without any cap. This vulnerability is fixed in 2.8.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opentelemetry

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
opentelemetry

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-15: 1Technical Details · 2026-06-15: 106-15
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve
    Disclosure

    🟠 Nodejs OpenTelemetry Core, Unbounded memory allocation in W3C Baggage propagation, #CVE-2026-54285 (Moderate) -DC-Jun2026-446 https://dailycve.com/nodejs-opentelemetry-core-unbounded-memory-allocation-in-w3c-baggage-propagation-cve-2026-54285-moderate-dc-jun2026-446/

    Post summary

    A new CVE-2026-54285 affects Nodejs OpenTelemetry Core, causing unbounded memory allocation through W3C Baggage propagation. The article is a disclosure with moderate severity but no PoC, exploit, or patch details provided.

    0000045
    212 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopentelemetryopentelemetry-node.js-

Explore more