OpenTelemetry Exporter Instana TLS Certificate Validation Vulnerability

Vulnerability

A vulnerability exists in the OpenTelemetry.Exporter.Instana NuGet package, affecting versions through 1.0.7. The issue arises because the exporter does not properly validate HTTPS/TLS certificates when sending telemetry to an Instana backend via a proxy, as specified by the INSTANA_ENDPOINT_PROXY environment variable. This flaw can be exploited by a network attacker who can intercept the proxy connection, leading to the exposure of OpenTelemetry telemetry data and the Instana API key.

Impact

Exploitation of this vulnerability allows a network attacker to intercept and read all telemetry data sent to Instana, along with the user's Instana API key. This could be done without any noticeable disruption of the telemetry data being sent, as the vulnerability bypasses important security measures in the TLS certificate validation process.

Remediation

Users can update to OpenTelemetry.Exporter.Instana version 1.1.0 or later, where this vulnerability has been fixed. In environments where the previous behavior is needed, such as local development, the vulnerability can be reintroduced by configuring the HttpClient to accept any server certificate.

Added: May 26, 2026, 11:48 PM
Updated: May 26, 2026, 11:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.2
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.