OpenTelemetry .NET Denial-of-Service Vulnerability in Trace Context Propagation

Vulnerability

A denial-of-service vulnerability has been identified in the OpenTelemetry.Api package, affecting versions 1.10.0 to 1.11.1. The issue arises when HTTP requests include tracestate and traceparent headers, leading to increased CPU usage. This vulnerability impacts web-accessible applications and backend services that process such headers, causing excessive resource consumption, higher latency, degraded performance, or potential downtime.

Impact

Excessive CPU usage from processing tracestate and traceparent headers, leading to increased application latency, degraded performance, or downtime.

Remediation

Users can upgrade to OpenTelemetry.Api version 1.11.2, which has been patched to prevent excessive CPU consumption from valid tracing headers. Affected versions have been delisted from NuGet to prevent accidental usage.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.