Advisories for Maven/Io.opentelemetry/Opentelemetry-Api package

2026

OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation

The practical availability impact for most deployments is limited. Every major Java HTTP server enforces its own header size limit (Tomcat, Jetty, Netty, Vert.x, and gRPC-Java all default to 8 KiB), constraining what an external attacker can deliver before the application is reached. The risk is higher when transport-layer limits are absent — e.g., a compromised internal service communicating over a non-HTTP or custom transport.