Two OpenTelemetry OTLP exporter implementations were found vulnerable to denial-of-service conditions that can exhaust application memory through malicious HTTP responses from a telemetry collector. CVE-2026-39882 affects the OpenTelemetry-Go OTLP HTTP exporters, where a compromised collector endpoint or an attacker performing a man-in-the-middle attack can keep the export connection open and stream an effectively infinite response body; the client buffers the payload during an io.Copy operation and can run out of memory before protocol parsing begins.
A related flaw, CVE-2026-40182, impacts the OpenTelemetry .NET OTLP exporter in opentelemetry-dotnet versions 1.13.1 through 1.15.1. In that case, error-handling logic reads an entire failed export response into memory for diagnostic logging when a collector rejects a request, allowing a malicious backend or adjacent-network attacker to trigger uncontrolled allocation and crash the host process. Proof-of-concept data for the Go issue showed unpatched clients peaking at 118,050,512 bytes of allocation with a 33,554,432-byte test payload, while patched clients used only 512,232 bytes under the same conditions.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A separate unbounded memory exhaustion denial-of-service flaw, tracked as CVE-2026-40182, was disclosed in the OpenTelemetry .NET OTLP exporter affecting opentelemetry-dotnet versions 1.13.1 through 1.15.1. The issue occurs when error-handling logic reads an entire failure response into memory for diagnostic logging, enabling memory exhaustion if an attacker controls or intercepts the backend endpoint.
A memory exhaustion denial-of-service vulnerability, tracked as CVE-2026-39882, was disclosed in the OpenTelemetry-Go OTLP HTTP exporters. The flaw allows a malicious or intercepted collector response to keep a connection open and stream an unbounded body, causing the client to buffer data until memory is exhausted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.