---
id: CVE-2026-45292
title: >-
  opentelemetry-java is the Java implementation of the OpenTelemetry API for
  recording telemetry, and SDK for managing telemetry recorded by the API
summary: >-
  opentelemetry-java is the Java implementation of the OpenTelemetry API for
  recording telemetry, and SDK for managing telemetry recorded by the API. Prior
  to 1.62.0, a vulnerability affects the baggage propagation implementation in
  opente…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-770
vendor: open-telemetry
product: opentelemetry-java
affected:
  - opentelemetry-java < 1.62.0
  - opentelemetry-api 1.62.0
  - opentelemetry-extension-trace-propagators 1.62.0
patched:
  - data_grid 8.6.2
  - migration_toolkit_for_applications 8.2
  - offline_knowledge_portal 1.2.4
  - openshift_ai 3.4
  - openshift_dev_spaces 3.29
published: '2026-05-28'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:20:17.357'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45292'
references:
  - url: >-
      https://github.com/open-telemetry/opentelemetry-java/commit/03837d3c1763bc35464aea1078671e2ef2336a5f
    label: security-advisories@github.com
  - url: 'https://github.com/open-telemetry/opentelemetry-java/pull/8380'
    label: security-advisories@github.com
  - url: 'https://github.com/open-telemetry/opentelemetry-java/releases/tag/v1.62.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/open-telemetry/opentelemetry-java/security/advisories/GHSA-rcgg-9c38-7xpx
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28573'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36820'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:41951'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:43038'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-45292'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2482785'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45292.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-45292'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45292'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - score-dispute
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-05-28T17:27:00.066477Z'
epss: 0.00849
epssPercentile: 0.56361
scores:
  nvd: 5.3
  vendor: 7.5
  cna: 5.3
ingestedAt: '2026-07-03T14:03:37.072Z'
---

## Overview

opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized baggage causes unbounded memory allocation and CPU consumption. Because baggage is automatically re-injected into every outgoing request, the effect can fan out to downstream services that never received the original malicious request. This vulnerability is fixed in 1.62.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:41951** · Red Hat · fixed in: Red Hat Data Grid 8.6.2 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:41951)
- **RHSA-2026:43038** · Red Hat · fixed in: Red Hat Migration Toolkit for Applications 8.2 · released 2026-07-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:43038)
- **RHSA-2026:28573** · Red Hat · fixed in: Red Hat Offline Knowledge Portal 1.2.4 · released 2026-06-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:28573)
- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **RHSA-2026:36820** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.29 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36820)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, OpenShift Serverless, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, … · no fix planned: Red Hat OpenShift AI (RHOAI), Exploit Intelligence, OpenShift Serverless, Red Hat build of Apache Camel 4 for Quarkus 3, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45292.json)
