Allocation of Resources Without Limits or Throttling Affecting @opentelemetry/core package, versions <2.8.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.24% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-OPENTELEMETRYCORE-17373280
  • published18 Jun 2026
  • disclosed15 Jun 2026
  • credittonghuaroot (童话)

Introduced: 15 Jun 2026

NewCVE-2026-54285  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade @opentelemetry/core to version 2.8.0 or higher.

Overview

@opentelemetry/core is an OpenTelemetry Core provides constants and utilities shared by all OpenTelemetry SDK packages.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the extract function. An attacker can cause excessive memory allocation by sending oversized baggage HTTP headers or equivalent data via non-HTTP transports.

Note: This is only exploitable if the deployment does not enforce transport-layer header size limits, such as when using custom transports or when default HTTP header size limits are increased.

Workaround

This vulnerability can be mitigated by configuring strict header size limits at the server or gateway level, or by validating input size before passing it to the propagator in non-HTTP transports.

CVSS Base Scores

version 4.0
version 3.1