OpenTelemetry.Exporter.Jaeger
Jaeger exporter for OpenTelemetry .NET
Activity
- Latest release
- 3y ago
- Total releases
- 58
- Cadence
- ~19 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Aug 03, 2019
| Version | Released | |
|---|---|---|
1.6.0-rc.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.6.0-rc.1
pre
Dependencies (4)
|
|
1.6.0-alpha.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.6.0-alpha.1
pre
Dependencies (4)
|
|
1.5.1
patch
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.5.1
patch
Dependencies (4)
|
|
1.5.0
minor
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.5.0
minor
Dependencies (4)
|
|
1.5.0-rc.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.5.0-rc.1
pre
Dependencies (4)
|
|
1.5.0-alpha.2
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.5.0-alpha.2
pre
Dependencies (3)
|
|
1.5.0-alpha.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.5.0-alpha.1
pre
Dependencies (3)
|
|
1.4.0
minor
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.4.0
minor
Dependencies (3)
|
|
1.4.0-rc.4
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.4.0-rc.4
pre
Dependencies (3)
|
|
1.4.0-rc.3
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.4.0-rc.3
pre
Dependencies (3)
|
|
1.4.0-rc.2
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.4.0-rc.2
pre
Dependencies (3)
|
|
1.3.2
patch
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.3.2
patch
Dependencies (3)
|
|
1.4.0-rc.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.4.0-rc.1
pre
Dependencies (3)
|
|
1.4.0-beta.3
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.4.0-beta.3
pre
Dependencies (3)
|
|
1.4.0-beta.2
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.4.0-beta.2
pre
Dependencies (3)
|
|
1.4.0-beta.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.4.0-beta.1
pre
Dependencies (3)
|
|
1.3.1
patch
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.3.1
patch
Dependencies (3)
|
|
1.4.0-alpha.2
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.4.0-alpha.2
pre
Dependencies (3)
|
|
1.4.0-alpha.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.4.0-alpha.1
pre
Dependencies (3)
|
|
1.3.0
minor
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.3.0
minor
Dependencies (3)
|
|
1.3.0-rc.2
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.3.0-rc.2
pre
Dependencies (3)
|
|
1.3.0-beta.2
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.3.0-beta.2
pre
Dependencies (2)
|
|
1.3.0-beta.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.3.0-beta.1
pre
Dependencies (2)
|
|
1.2.0
minor
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0
minor
Dependencies (2)
|
|
1.2.0-rc5
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0-rc5
pre
Dependencies (2)
|
|
1.2.0-rc4
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0-rc4
pre
Dependencies (2)
|
|
1.2.0-rc3
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0-rc3
pre
Dependencies (2)
|
|
1.2.0-rc2
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0-rc2
pre
Dependencies (2)
|
|
1.2.0-rc1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0-rc1
pre
Dependencies (2)
|
|
1.2.0-beta2.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0-beta2.1
pre
Dependencies (2)
|
|
1.2.0-beta1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0-beta1
pre
Dependencies (2)
|
|
1.2.0-alpha4
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0-alpha4
pre
Dependencies (2)
|
|
1.2.0-alpha3
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0-alpha3
pre
Dependencies (2)
|
|
1.2.0-alpha2
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0-alpha2
pre
Dependencies (2)
|
|
1.2.0-alpha1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.2.0-alpha1
pre
Dependencies (2)
|
|
1.1.0
minor
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.1.0
minor
Dependencies (2)
|
|
1.1.0-rc1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.1.0-rc1
pre
Dependencies (2)
|
|
1.1.0-beta4
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.1.0-beta4
pre
Dependencies (2)
|
|
1.1.0-beta3
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.1.0-beta3
pre
Dependencies (2)
|
|
1.1.0-beta2
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.1.0-beta2
pre
Dependencies (2)
|
|
1.1.0-beta1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.1.0-beta1
pre
Dependencies (2)
|
|
1.0.1
initial
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.0.1
initial
Dependencies (2)
|
|
1.0.0-rc4
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.0.0-rc4
pre
Dependencies (2)
|
|
1.0.0-rc3
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.0.0-rc3
pre
Dependencies (2)
|
|
1.0.0-rc2
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.0.0-rc2
pre
Dependencies (2)
|
|
1.0.0-rc1.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
1.0.0-rc1.1
pre
Dependencies (2)
|
|
0.8.0-beta.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
0.8.0-beta.1
pre
Dependencies (2)
|
|
0.7.0-beta.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
0.7.0-beta.1
pre
Dependencies (2)
|
|
0.6.0-beta.1
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
0.6.0-beta.1
pre
Dependencies (2)
|
|
0.5.0-beta.2
pre
1 CVE
CVE-2026-41078
GHSA-38h3-2333-qx47
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summary
DetailsThe Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service. ImpactAvailability impact only. Confidentiality and integrity impacts are not expected. Workarounds / Mitigations
Affected versions
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.1.0
1.1.0-beta1
1.1.0-beta2
1.1.0-beta3
1.1.0-beta4
1.1.0-rc1
1.2.0
1.2.0-alpha1
+ 15 more Show less
1.2.0-alpha2
1.2.0-alpha3
1.2.0-alpha4
1.2.0-beta1
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.0-rc4
1.2.0-rc5
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
References Updated May 05, 2026 · Source: OSV.dev |
0.5.0-beta.2
pre
Dependencies (2)
|