Allocation of Resources Without Limits or Throttling Affecting opentelemetry.exporter.jaeger package, versions [0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DOTNET-OPENTELEMETRYEXPORTERJAEGER-16109572
  • published19 Apr 2026
  • disclosed18 Apr 2026
  • creditKielek

Introduced: 18 Apr 2026

CVE-2026-41078  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

There is no fixed version for OpenTelemetry.Exporter.Jaeger.

Overview

OpenTelemetry.Exporter.Jaeger is a Jaeger exporter for OpenTelemetry .NET

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling through the span and tag conversion. An attacker can drive sustained memory pressure and denial of service by supplying telemetry with unusually large or high-cardinality span attributes, events, or tags, causing the pooled list size to grow and then be reused for later allocations.

Workarounds

  • There is no plan to fix this issue as OpenTelemetry.Exporter.Jaeger was deprecated in 2023. Prefer a maintained exporter, such as OpenTelemetry Protocol (OTLP), over OpenTelemetry.Exporter.Jaeger.

CVSS Base Scores

version 4.0
version 3.1