Executive brief
A vulnerability in the OpenTelemetry .NET exporter library could allow a local attacker on a shared system to intercept or manipulate monitoring data. The library, which is used to send application performance and health data to monitoring services, incorrectly used a shared temporary folder to store data during network failures. This could lead to the exposure of sensitive application logs and metrics, the injection of fake monitoring data, or a denial-of-service by filling up disk space.
Technical details
The vulnerability exists in the OTLP disk retry feature of OpenTelemetry.Exporter.OpenTelemetryProtocol (versions 1.8.0 to 1.15.2). When the 'disk' retry mode is enabled without a specific directory path configured, the exporter defaults to using the system's shared temporary directory (Path.GetTempPath()). Because the subdirectories used (traces, metrics, logs) are predictable and often lack restrictive permissions on multi-user systems, a local attacker can perform 'blob injection' by placing malicious telemetry files into these folders, which the application will then sign and forward. Additionally, attackers can read existing telemetry blobs to steal sensitive data or perform resource exhaustion by flooding the directory with large files. The issue is resolved in version 1.15.3 by requiring an explicit, secure directory path when disk retry is enabled.
Affected products
- OpenTelemetry OpenTelemetry.Exporter.OpenTelemetryProtocol 1.8.0 to 1.15.2
Timeline
- 2026-04-17: patched: Pull request merged to fix insecure default path
- 2026-04-27: advisory: Vendor security advisory published via GitHub
- 2026-05-12: disclosed: CVE-2026-42191 published to NVD