Executive brief
OpenTelemetry.OpAmp.Client is a .NET library used to manage and configure OpenTelemetry agents. A vulnerability in how it handles server communications allows a malicious or compromised server to send an excessively large response that exhausts the application's memory. This can lead to a denial-of-service (DoS) condition, causing the application to crash or become unresponsive.
Technical details
The OpenTelemetry.OpAmp.Client library for .NET (prior to version 0.2.0-alpha.1) contains a memory allocation vulnerability (CWE-789) in its HTTP transport implementation. The client uses 'ReadAsByteArrayAsync' to process 'HttpResponseMessage.Content' without an upper bound on the number of bytes consumed. An attacker who controls the OpAMP server, or a network attacker capable of a Man-in-the-Middle (MitM) attack, can return an extremely large response body to trigger memory exhaustion in the consuming application. This results in a denial-of-service (DoS) condition. The issue was addressed in version 0.2.0-alpha.1 by implementing a 128KB limit on response sizes.
Affected products
- OpenTelemetry OpenTelemetry.OpAmp.Client < 0.2.0-alpha.1
Timeline
- 2026-04-16: patched: Fix merged in pull request #4116
- 2026-04-27: advisory: GitHub Security Advisory published
- 2026-05-12: disclosed: CVE-2026-42348 published to NVD