Executive brief
OpenTelemetry.Exporter.Zipkin is a .NET library used to export application performance data to the Zipkin tracing system. A vulnerability in how it handles remote endpoint data allows for uncontrolled memory growth when processing a large number of unique service names. This can lead to increased memory pressure and potential application crashes or performance degradation, impacting the availability of the monitored service.
Technical details
The Zipkin exporter in OpenTelemetry .NET (versions 1.15.2 and earlier) utilizes an unbounded cache for remote endpoints derived from span attributes. In scenarios with high-cardinality data—where unique remote endpoint values are frequently generated—the cache grows indefinitely. An attacker or high-volume environment can trigger this by providing sustained unique service names, leading to memory exhaustion (CWE-400/CWE-770). The vulnerability is exploited via the network as the exporter processes incoming span data. The fix in version 1.15.3 introduces a thread-safe Least Recently Used (LRU) cache with a fixed maximum size of 1024 entries and adds capacity guards for serialization buffers.
Affected products
- OpenTelemetry OpenTelemetry.Exporter.Zipkin <= 1.15.2
Timeline
- 2026-04-15: other: Pull request to fix the issue submitted
- 2026-04-27: advisory: GitHub Security Advisory published
- 2026-05-06: disclosed: CVE published to NVD