News KrakenD Partners with Digital Platform Solutions to Expand Reach in Pakistan

CVE-2026-39882 Medium · CVSS 5.3 Low Impact

telemetry/opentelemetry: OTLP HTTP Exporter Reads Unbounded Response Body

Limited exploitability

Exploiting this CVE requires an uncommon setup or configuration. Upgrading is still recommended when possible.

This CVE only affects deployments with OpenTelemetry tracing or metrics enabled using OTLP HTTP exporters (telemetry/opentelemetry in the KrakenD configuration with an OTLP HTTP endpoint). Exploitation requires the ability to control or intercept traffic to the configured OTLP collector endpoint.

Component

telemetry/opentelemetry (OTLP HTTP exporters)

Disclosed

May 11, 2026

CVSS Score

5.3

Description

The OTLP HTTP exporters in OpenTelemetry-Go read the full HTTP response body into memory without enforcing a size limit. If the OTLP collector endpoint is compromised or network traffic is intercepted, an attacker controlling the collector can return an arbitrarily large response body, causing memory exhaustion and denial of service in the exporting process.

Version summary

Community Edition

2.13.5

addresses this CVE

Affected CE versions

>= 2.0, < 2.13.5

Enterprise Edition

2.13.3

addresses this CVE

Affected EE versions

>= 2.0, < 2.13.3

Upgrade to the addressed version or later to remediate this vulnerability.

Stay up to date with KrakenD releases and important updates