CVE-2026-41310: OpenTelemetry .NET Zipkin exporter has unbounded remote endpoint cache leading to memory growth

Published Apr 28, 2026
·
Updated

Summary

The Zipkin exporter remote endpoint cache accepted unbounded key growth derived from span attributes. In high-cardinality scenarios, this could increase process memory usage over time and degrade availability.

Details

- Introduce a bounded, thread-safe LRU cache for remote endpoints. - Enforce fixed maximum size to prevent unbounded growth.

Impact

- A process using Zipkin export for client/producer spans could experience avoidable memory growth under sustained unique remote endpoint values.

Resources

#7081

Other sources

OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cache accepts unbounded key growth derived from span attributes. In high-cardinality scenarios, a process using Zipkin export for client or producer spans could experience avoidable memory growth under sustained unique remote endpoint values, increasing process memory usage over time and degrading availability. This issue is fixed in version 1.15.3, which introduces a bounded, thread-safe LRU cache for remote endpoints with a fixed maximum size.

MITRE

Affected Software

2 affected componentsFixes available
nuget/OpenTelemetry.Exporter.Zipkin<=1.15.2
1.15.3
OpenTelemetry Opentelemetry.exporter.zipkin .net<1.15.3

Event History

Apr 28, 2026
Advisory Published
via GitHub·11:23 PM
Data Sourced
via GitHub·11:23 PM
DescriptionSeverityWeaknessAffected Software
May 6, 2026
CVE Published
via MITRE·08:54 PM
Data Sourced
via MITRE·08:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-41310?

CVE-2026-41310 is considered a moderate severity vulnerability due to its potential to increase memory usage and degrade application availability.

2

How do I fix CVE-2026-41310?

To fix CVE-2026-41310, upgrade to OpenTelemetry.Exporter.Zipkin version 1.15.3 or later.

3

What causes CVE-2026-41310?

CVE-2026-41310 is caused by unbounded key growth in the Zipkin exporter remote endpoint cache due to high-cardinality span attributes.

4

Which versions are affected by CVE-2026-41310?

Versions of OpenTelemetry.Exporter.Zipkin up to and including 1.15.2 are affected by CVE-2026-41310.

5

What are the implications of CVE-2026-41310?

The implications of CVE-2026-41310 include increased memory usage over time, which may lead to performance issues or application crashes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203