CVE-2026-41483 Details
Description
OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequestor class makes HTTP requests to the Azure VM instance metadata service and reads the response body into memory without any size limit. An attacker who controls the configured endpoint, or who can intercept traffic to it via a man-in-the-middle attack, can return an arbitrarily large response body. This causes unbounded heap allocation in the consuming process, leading to high transient memory pressure, garbage-collection stalls, or an OutOfMemoryException that terminates the process. As a workaround, disable the Azure VM resource detector or use network-level controls such as firewall rules, mTLS, or a service mesh to prevent man-in-the-middle attacks on the Azure VM instance metadata endpoint. This issue is fixed in version 1.15.1-beta.1, which streams responses rather than buffering them entirely in memory and ignores responses larger than 4 MiB.
A denial-of-service vulnerability has been identified in OpenTelemetry.Resources.Azure, specifically in versions through 1.15.0-beta.1. The issue arises in the AzureVmMetaDataRequestor class, which makes HTTP requests to the Azure VM instance metadata service without limiting the size of the response. This flaw allows an attacker controlling the endpoint or intercepting the traffic to cause excessive memory allocation, leading to high memory pressure, garbage collection delays, or an OutOfMemoryException that crashes the process.
The vulnerability is fixed in OpenTelemetry.Resources.Azure version 1.15.1-beta.1, which streams HTTP responses instead of buffering them entirely in memory and ignores responses larger than 4 MiB. As a workaround, the Azure VM resource detector can be disabled, or network-level controls such as firewall rules, mTLS, or a service mesh can be used to prevent man-in-the-middle attacks on the Azure VM instance metadata endpoint.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4121 | [email protected] | Issue TrackingPatch |
| https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisories/GHSA-vc24-j8c5-2vw4 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| opentelemetry opentelemetry.resources.azure | <= 1.15.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 6, 2026 | New CVE Received | [email protected] |