Junglewise Threat Intelligence

CVE-2026-54285: OpenTelemetry opentelemetry-js unbounded memory allocation in W3C Baggage

CVE-2026-54285 · Severity: medium · CVSS 5.3 · Published 2026-06-22

Vendors: Opentelemetry, npm.

Executive brief

OpenTelemetry is a popular framework used by developers to monitor and trace the performance of their applications. A vulnerability in its JavaScript library allows an attacker to send specially crafted, oversized data headers that cause the application to consume excessive memory. While standard web server settings often limit this risk, an exploit could potentially lead to slowed performance or service crashes in environments with custom configurations or non-standard data transports.

Technical details

The W3CBaggagePropagator.extract() function in @opentelemetry/core fails to enforce the W3C Baggage specification's recommended limits (8,192 bytes and 180 entries) on inbound paths. While outbound injection was restricted, inbound extraction allows for memory allocation proportional to the header size without a cap. An unauthenticated remote attacker can exploit this by sending oversized baggage headers. The impact is partially mitigated in default Node.js environments by the --max-http-header-size limit (16 KB), but the risk remains significant for non-HTTP transports or deployments with increased header limits. The issue is resolved in version 2.8.0 by enforcing strict size and entry counts during extraction.

Affected products

  • OpenTelemetry opentelemetry-js (@opentelemetry/core) < 2.8.0

Timeline

  • 2026-06-12: advisory: GitHub Security Advisory published
  • 2026-06-22: disclosed: CVE published to NVD

References