A vulnerability in opentelemetry-java, prior to version 1.62.0, affects the baggage propagation implementation, allowing for unbounded memory allocation and CPU consumption when parsing oversized baggage. This can lead to a denial of service (DoS) attack, potentially impacting downstream services. The vulnerability is fixed in version 1.62.0. Defenders should assess exposure and prioritize upgrading to ve [truncated]
A vulnerability in the OpenTelemetry JavaScript Prometheus exporter allows remote attackers to crash Node.js processes via malformed HTTP requests. The metrics endpoint (default 0.0.0.0:9464) lacks error handling for URL parsing, causing an uncaught TypeError that terminates the process. This affects versions prior to 0.217.0. The vulnerability was published on 2026-05-27 and carries a HIGH severity CVSS [truncated]