Advisory Database
  • Advisories
  • Dependency Scanning
  1. nuget
  2. ›
  3. OpenTelemetry.Exporter.Zipkin
  4. ›
  5. CVE-2026-41310

CVE-2026-41310: OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure

April 28, 2026 (updated May 8, 2026)

The Zipkin exporter remote endpoint cache accepted unbounded key growth derived from span attributes. In high-cardinality scenarios, this could increase process memory usage over time and degrade availability.

References

  • github.com/advisories/GHSA-88hf-wf7h-7w4m
  • github.com/open-telemetry/opentelemetry-dotnet
  • github.com/open-telemetry/opentelemetry-dotnet/commit/c724f4bd6fd88e9a599af1668bf7af9487155b62
  • github.com/open-telemetry/opentelemetry-dotnet/pull/7081
  • github.com/open-telemetry/opentelemetry-dotnet/security/advisories/GHSA-88hf-wf7h-7w4m
  • nvd.nist.gov/vuln/detail/CVE-2026-41310

Code Behaviors & Features

Detect and mitigate CVE-2026-41310 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.15.3

Fixed versions

  • 1.15.3

Solution

Upgrade to version 1.15.3 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption
  • CWE-770: Allocation of Resources Without Limits or Throttling

Source file

nuget/OpenTelemetry.Exporter.Zipkin/CVE-2026-41310.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:19:16 +0000.