CVE-2026-45292
Last modified
CVE-2026-45292 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. EPSS estimates a 1.10% chance of exploitation in the next 30 days.
Description
opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized baggage causes unbounded memory allocation and CPU consumption. Because baggage is automatically re-injected into every outgoing request, the effect can fan out to downstream services that never received the original malicious request. This vulnerability is fixed in 1.62.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| open-telemetry | opentelemetry-java | < 1.62.0 |
| io.opentelemetry | opentelemetry-api | 1.62.0 |
| io.opentelemetry | opentelemetry-extension-trace-propagators | 1.62.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-45292?
How severe is CVE-2026-45292?
How do I fix CVE-2026-45292?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-45287OpenTelemetry-Go is the Go implementation of OpenTelemetry. …5.5
- CVE-2026-45288Marten is a .NET Transactional Document DB and Event Store o…9.8
- CVE-2026-45289CloudburstMC Protocol is a protocol library for Minecraft Be…5.3
- CVE-2026-4529A vulnerability was identified in D-Link DHP-1320 1.00WWB04.…8.8
- CVE-2026-45290Cloudburst Network provides network components used within C…7.5
- CVE-2026-45291Cloudburst Network provides network components used within C…7.5
- CVE-2026-45293WordPress Coding Standards is a set of PHP_CodeSniffer rules…8.6
- CVE-2026-45294FreeScout is a free help desk and shared inbox built with PH…5.3
- CVE-2026-45295FreeScout is a free help desk and shared inbox built with PH…6.5
- CVE-2026-45296OpenReplay is a self-hosted session replay suite. Prior to 1…7.7
- CVE-2026-45297OpenReplay is a self-hosted session replay suite. Prior to 1…5.3
- CVE-2026-45298Dozzle is a realtime log viewer for docker containers. Prior…8.6
Are you affected by CVE-2026-45292?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
