CVE Explorer
CVE-2026-41483
OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequestor class makes HTTP requests to the Azure VM instance metadata service and reads the response body into memory without any size limit. An attacker who controls the configured endpoint, or who can intercept traffic to it via a man-in-the-middle attack, can return an arbitrarily large response body. This causes unbounded heap allocation in the consumi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"opentelemetry-dotnet-contrib","vendor":"open-telemetry","versions":[{"status":"affected","version":"<= 1.15.0-beta.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:01a95e38c5e4ef6dbc2d30f73e10ffb87e18f8d109cbb1b22965ff663c57e6c7 · sha256:589d4c282726d240… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:01a95e38c5e4ef6dbc2d30f73e10ffb87e18f8d109cbb1b22965ff663c57e6c7 · sha256:589d4c282726d240… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-770","description":"CWE-770: Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:01a95e38c5e4ef6dbc2d30f73e10ffb87e18f8d109cbb1b22965ff663c57e6c7 · sha256:589d4c282726d240… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4121","tags":["x_refsource_MISC"],"url":"https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4121"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:01a95e38c5e4ef6dbc2d30f73e10ffb87e18f8d109cbb1b22965ff663c57e6c7 · sha256:589d4c282726d240… · /containers/cna/references/1
{"name":"https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisories/GHSA-vc24-j8c5-2vw4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisories/GHSA-vc24-j8c5-2vw4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:01a95e38c5e4ef6dbc2d30f73e10ffb87e18f8d109cbb1b22965ff663c57e6c7 · sha256:589d4c282726d240… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.