


Perceptive Security
SOC/SIEM Consultancy

opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry…
Published:
26 May 2026 at 22:00:00
Alert date:
27 May 2026 at 16:03:27
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
CVE-2026-44902 affects OpenTelemetry JavaScript Client prior to version 0.217.0. A single malformed HTTP request can crash any Node.js process running the OpenTelemetry JS Prometheus exporter. The vulnerability exists in the metrics endpoint (default 0.0.0.0:9464) which lacks error handling around URL parsing. When an invalid URI is sent in a request, it causes an uncaught TypeError that terminates the entire process. This represents a denial of service vulnerability that can be triggered by a single malicious request. The issue has been patched in version 0.217.0.
Technical details
Mitigation steps:
Affected products:
OpenTelemetry JavaScript Client
Node.js
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44902
https://github.com/open-telemetry/opentelemetry-js/security/advisories/GHSA-q7rr-3cgh-j5r3
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
