opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid URI causes an uncaught TypeError that terminates the process. This vulnerability is fixed in 0.217.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| @Opentelemetry | Auto-Instrumentations-Node | < 0.75.0CNA affected | |
| @Opentelemetry | Exporter-Prometheus | < 0.217.0CNA affected | |
| Open-Telemetry | Opentelemetry-Js | < 0.217.0CNA affected | |
| @Opentelemetry | Sdk-Node | < 0.217.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.