top of page
perceptive_background_267k.jpg

opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry…

Published:

26 May 2026 at 22:00:00

Alert date:

27 May 2026 at 16:03:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

CVE-2026-44902 affects OpenTelemetry JavaScript Client prior to version 0.217.0. A single malformed HTTP request can crash any Node.js process running the OpenTelemetry JS Prometheus exporter. The vulnerability exists in the metrics endpoint (default 0.0.0.0:9464) which lacks error handling around URL parsing. When an invalid URI is sent in a request, it causes an uncaught TypeError that terminates the entire process. This represents a denial of service vulnerability that can be triggered by a single malicious request. The issue has been patched in version 0.217.0.

Technical details

Mitigation steps:

Affected products:

OpenTelemetry JavaScript Client
Node.js

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page