OpenTelemetry .NET Denial-of-Service Vulnerability in Trace Context Propagation
Vulnerability
A denial-of-service vulnerability has been identified in the OpenTelemetry.Api package, affecting versions 1.10.0 to 1.11.1. The issue arises when HTTP requests include tracestate and traceparent headers, leading to increased CPU usage. This vulnerability impacts web-accessible applications and backend services that process such headers, causing excessive resource consumption, higher latency, degraded performance, or potential downtime.
Impact
Excessive CPU usage from processing tracestate and traceparent headers, leading to increased application latency, degraded performance, or downtime.
Remediation
Users can upgrade to OpenTelemetry.Api version 1.11.2, which has been patched to prevent excessive CPU consumption from valid tracing headers. Affected versions have been delisted from NuGet to prevent accidental usage.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
