CVE-2026-41078: OpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path

Published Apr 18, 2026
·
Updated

Summary

> [!IMPORTANT] > There is no plan to fix this issue as OpenTelemetry.Exporter.Jaeger was deprecated in 2023. It is for informational purposes only.

OpenTelemetry.Exporter.Jaeger may allow sustained memory pressure when the internal pooled-list sizing grows based on a large observed span/tag set and that enlarged size is reused for subsequent allocations. Under high-cardinality or attacker-influenced telemetry input, this can increase memory consumption and potentially cause denial of service.

Details

The Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influenced by large observed payloads and reused globally across later allocations, resulting in persistent oversized rentals and elevated memory pressure. In environments where telemetry attributes/events can be influenced by untrusted input and limits are increased from defaults, this may lead to process instability or denial of service.

Impact

Availability impact only. Confidentiality and integrity impacts are not expected.

Workarounds / Mitigations

Prefer maintained exporters (for example OpenTelemetry Protocol format (OTLP)) instead of the Jaeger exporter.

Other sources

OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow sustained memory pressure when the internal pooled-list sizing grows based on a large observed span/tag set and that enlarged size is reused for subsequent allocations. Under high-cardinality or attacker-influenced telemetry input, this can increase memory consumption and potentially cause denial of service. There is no plan to fix this issue as OpenTelemetry.Exporter.Jaeger was deprecated in 2023.

MITRE

Affected Software

7 affected components
nuget/OpenTelemetry.Exporter.Jaeger<=1.6.0-rc.1
OpenTelemetry OpenTelemetry .NET<1.6.0
OpenTelemetry OpenTelemetry .NET=1.6.0-alpha1
OpenTelemetry OpenTelemetry .NET=1.6.0-beta1
OpenTelemetry OpenTelemetry .NET=1.6.0-beta2
OpenTelemetry OpenTelemetry .NET=1.6.0-beta3
OpenTelemetry OpenTelemetry .NET=1.6.0-rc1

Event History

Apr 18, 2026
Advisory Published
via GitHub·01:05 AM
Data Sourced
via GitHub·01:05 AM
DescriptionSeverityWeaknessAffected Software
Apr 23, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-41078?

The CVE-2026-41078 vulnerability does not have a severity rating as it is informational only.

2

How do I fix CVE-2026-41078?

There is no fix for CVE-2026-41078 as OpenTelemetry.Exporter.Jaeger has been deprecated since 2023.

3

What impact does CVE-2026-41078 have on my application?

CVE-2026-41078 may cause sustained memory pressure due to internal pooled-list sizing in OpenTelemetry.Exporter.Jaeger.

4

Which versions of OpenTelemetry are affected by CVE-2026-41078?

CVE-2026-41078 affects OpenTelemetry.Exporter.Jaeger version 1.6.0-rc.1 and below.

5

Is there a recommended alternative to OpenTelemetry.Exporter.Jaeger due to CVE-2026-41078?

Consider using other supported OpenTelemetry exporters, as OpenTelemetry.Exporter.Jaeger has been deprecated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203