CyberSec.Space Logo
返回 CVE 浏览器

CVE-2026-44967

MEDIUM
5.3
CVSS Severity Score
EPSS Score0.0800%
EPSS Percentile25.06th
Published2026年6月12日
Last Modified2026年6月12日

Vulnerability Description

OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can MITM the exporter connection). This vulnerability is fixed in opentelemetry-cpp release 1.27.0.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相关漏洞威胁