Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90080.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-90080
Upstream
Published
2026-06-12T16:16:27Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-44967 affecting package opentelemetry-cpp for versions less than 1.14.2-3
Details

OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can MITM the exporter connection). This vulnerability is fixed in opentelemetry-cpp release 1.27.0.

References

Affected packages

Azure Linux:3 / opentelemetry-cpp

Package

Name
opentelemetry-cpp
Purl
pkg:rpm/azure-linux/opentelemetry-cpp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.14.2-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90080.json"