Signal is active with 1 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed percent-encoded value that throws an uncaught URIError and terminates a Node.js process using JaegerPropagator as the active propagator. This issue is fixed in version 2.9.0.
Peaked 1d ago at 1 mentions (2026-07-09); latest day: 1
2 total mentions across 2 days
Deep dive
>Activity timeline2 mentions / 2d
>Signal classification1 categories
Patch
2100.0%
>Full discourse2 posts
DFIR Lab@DFIR_Lab·
Patch
🚨 HIGH: CVE-2026-59892 (CVSS 7.5)
OpenTelemetry JavaScript JaegerPropagator vulnerable to DoS via malformed HTTP headers. Unauthenticated attackers can crash Node.js processes.
Fixed in v2.9.0 - UPDATE NOW
#CVE#PatchNow#ThreatIntel https://t.co/jDaQCzWRuU
Post summary
The tweet alerts to CVE-2026‑59892—a DoS flaw in OpenTelemetry JavaScript JaegerPropagator that crashes Node.js via malformed HTTP headers—and urges users to apply the v2.9.0 patch.
🚨 HIGH - OpenTelemetry Jaeger propagator DoS via malformed header decoding (CVE-2026-59892)
OpenTelemetry JavaScript’s @opentelemetry/propagator-jaeger improperly decodes incoming uber-trace-id and uberctx-* HTTP headers using decodeURIComponent() without safely handling decode failures. The root cause is missing exception handling / improper input validation leading to an uncaught URIError on malformed percent-encoded input. An unauthenticated remote attacker can exploit this by sending crafted HTTP requests with invalid percent-encoding in those headers to any service where JaegerPropagator is enabled in the request processing path. Successful exploitation results in a denial of service by crashing/terminating the Node.js process, causing immediate outage and potential cascading failures in upstream systems.
👉 Affected: @opentelemetry/propagator-jaeger < 2.9.0 | Upgrade to 2.9.0
Post summary
High‑severity DoS vulnerability in OpenTelemetry JavaScript Jaeger propagator is caused by decoding malformed headers and can trigger a Node.js crash. The fix is to upgrade to version 2.9.0.