Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 12 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can MITM the exporter connection). This vulnerability is fixed in opentelemetry-cpp release 1.27.0. | |
| Title | opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response | |
| Weaknesses | CWE-789 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-12T16:10:48.362Z
Reserved: 2026-05-08T16:23:33.263Z
Link: CVE-2026-44967
Updated: 2026-06-12T16:10:40.139Z
Status : Awaiting Analysis
Published: 2026-06-12T16:16:27.973
Modified: 2026-06-12T17:16:23.020
Link: CVE-2026-44967
No data.
OpenCVE Enrichment
Updated: 2026-06-12T16:30:14Z