Junglewise Threat Intelligence

CVE-2026-44213: OpenTelemetry.Exporter.Instana improper TLS certificate validation via proxy

CVE-2026-44213 · Severity: medium · CVSS 6.5 · Published 2026-05-26

Vendors: Opentelemetry, NuGet.

Executive brief

A vulnerability in the OpenTelemetry Instana exporter library causes it to stop verifying security certificates when a network proxy is used. This allows an attacker who can intercept network traffic to read sensitive monitoring data and steal the Instana API key. This could lead to the exposure of internal application performance data and unauthorized access to the organization's Instana monitoring account.

Technical details

The vulnerability exists in the Transport.ConfigureBackendClient() method of the OpenTelemetry.Exporter.Instana library. When the INSTANA_ENDPOINT_PROXY environment variable is set, the library creates an HttpClient instance that explicitly disables TLS server certificate validation. A network-positioned attacker or one who controls the proxy can perform a Man-in-the-Middle (MitM) attack to intercept telemetry traffic and the Instana API key. The issue is fixed in version 1.1.0 by ensuring certificate validation remains enabled by default even when a proxy is in use.

Affected products

  • OpenTelemetry OpenTelemetry.Exporter.Instana <= 1.0.7

Timeline

  • 2026-05-06: disclosed
  • 2026-05-08: advisory
  • 2026-05-26: other: Published to NVD

References