云虫漏洞库

CVE-2026-45292 - opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized baggage causes unbounded memory allocation and CPU consumption. Because baggage is automatically re-injected into every outgoing request, the effect can fan out to downs - 漏洞详情

漏洞编号:CVE-2026-45292

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-45292

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-770

发布/更新时间:2026-05-28 / 2026-08-28

漏洞描述

opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized baggage causes unbounded memory allocation and CPU consumption. Because baggage is automatically re-injected into every outgoing request, the effect can fan out to downstream services that never received the original malicious request. This vulnerability is fixed in 1.62.0.

相关链接

相关漏洞

« 返回首页