DEBIAN-CVE-2026-44967

Source
https://security-tracker.debian.org/tracker/CVE-2026-44967
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44967.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-44967
Upstream
Published
2026-06-12T16:16:27Z
Modified
2026-09-19T05:00:10Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can MITM the exporter connection). This vulnerability is fixed in opentelemetry-cpp release 1.27.0.

References

Affected packages

Debian:13 / opentelemetry-cpp

Package

Name
opentelemetry-cpp
Purl
pkg:deb/debian/opentelemetry-cpp?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.19.0-3
1.23.0-1
1.23.0-2
1.23.0-3
1.28.0-1
1.28.0-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44967.json"

Debian:14 / opentelemetry-cpp

Package

Name
opentelemetry-cpp
Purl
pkg:deb/debian/opentelemetry-cpp?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.28.0-1

Affected versions

1.*
1.19.0-3
1.23.0-1
1.23.0-2
1.23.0-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44967.json"