CVE-2026-41310
Last modified
CVE-2026-41310 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cache accepts unbounded key growth derived from span attributes. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cache accepts unbounded key growth derived from span attributes. In high-cardinality scenarios, a process using Zipkin export for client or producer spans could experience avoidable memory growth under sustained unique remote endpoint values, increasing process memory usage over time and degrading availability. This issue is fixed in version 1.15.3, which introduces a bounded, thread-safe LRU cache for remote endpoints with a fixed maximum size.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opentelemetry | Opentelemetry.Exporter.Zipkin | < 1.15.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-41310?
How severe is CVE-2026-41310?
How do I fix CVE-2026-41310?
Are you affected by CVE-2026-41310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
