Generated remediation guidance and an executive summary. No account required.
OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.
Cite this page
CVE-2026-40894. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-40894
Use CWE-789, Opentelemetry vendor hub and Opentelemetry product page to widen CVE-2026-40894 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-29181, CVE-2023-47108 and CVE-2023-45142 for nearby disclosures in the same product family.