Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-27513

Опубликовано: 05 мар. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTelemetry.Api package 1.10.0 to 1.11.1 could cause a Denial of Service (DoS) when a tracestate and traceparent header is received. Even if an application does not explicitly use trace context propagation, receiving these headers can still trigger high CPU usage. This issue impacts any application accessible over the web or backend services that process HTTP requests containing a tracestate header. Application may experience excessive resource consumption, leading to increased latency, degraded performance, or downtime. This vulnerability is fixed in 1.11.2.

EPSS

Процентиль: 24%
0.00081
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 6.5
github
11 месяцев назад

OpenTelemetry .NET has Denial of Service (DoS) Vulnerability in API Package

EPSS

Процентиль: 24%
0.00081
Низкий

7.5 High

CVSS3

Дефекты

CWE-770