{"id":"AZL-90080","summary":"CVE-2026-44967 affecting package opentelemetry-cpp for versions less than 1.14.2-3","details":"OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can MITM the exporter connection). This vulnerability is fixed in opentelemetry-cpp release 1.27.0.","modified":"2026-08-30T05:26:50Z","published":"2026-06-12T16:16:27Z","upstream":["CVE-2026-44967"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44967"}],"affected":[{"package":{"name":"opentelemetry-cpp","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/opentelemetry-cpp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14.2-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90080.json"}}],"schema_version":"1.9.0"}