opentelemetry-js: Prometheus exporter process crash via malformed HTTP request
Published May 27, 2026
7.5
HIGHCVSS 3.1
EPSS 0.49%
Description
opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid URI causes an uncaught TypeError that terminates the process. This vulnerability is fixed in 0.217.0.
Affected products
-
- Version < 0.217.0StatusaffectedConstraints-
- Version
- Vendor n/a Product Auto-Instrumentations-Node Defaultn/a
- Version < 0.75.0StatusaffectedConstraints-
- Version
- Vendor n/a Product Exporter-Prometheus Defaultn/a
- Version < 0.217.0StatusaffectedConstraints-
- Version
- Vendor n/a Product Sdk-Node Defaultn/a
- Version < 0.217.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Open-Telemetry | Opentelemetry-JS | n/a |
| ||||||
| n/a | Auto-Instrumentations-Node | n/a |
| ||||||
| n/a | Exporter-Prometheus | n/a |
| ||||||
| n/a | Sdk-Node | n/a |
|
- < 0.75.0
- < 0.217.0
- < 0.217.0
No data.
Red Hat Ansible Automation Platform 2.2
ansible-automation-platform/bootc-automation-portal-rhel9:1786006573
Fixed · RHSA-2026:51162
Red Hat Developer Hub 1.9
rhdh/rhdh-hub-rhel9:1784210921
Fixed · RHSA-2026:41929
Red Hat Hardened Images
nodejs20
Not affected
Red Hat Hardened Images
nodejs22
Not affected
Red Hat Hardened Images
nodejs24
Not affected
Red Hat Hardened Images
nodejs25
Not affected
Red Hat Hardened Images
nodejs26
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2.2 | ansible-automation-platform/bootc-automation-portal-rhel9:1786006573 | Fixed | RHSA-2026:51162 |
| Red Hat Developer Hub 1.9 | rhdh/rhdh-hub-rhel9:1784210921 | Fixed | RHSA-2026:41929 |
| Red Hat Hardened Images | nodejs20 | Not affected | n/a |
| Red Hat Hardened Images | nodejs22 | Not affected | n/a |
| Red Hat Hardened Images | nodejs24 | Not affected | n/a |
| Red Hat Hardened Images | nodejs25 | Not affected | n/a |
| Red Hat Hardened Images | nodejs26 | Not affected | n/a |
@opentelemetry/exporter-prometheus
npm
Introduced 0 Fixed 0.217.0@opentelemetry/sdk-node
npm
Introduced 0 Fixed 0.217.0@opentelemetry/auto-instrumentations-node
npm
Introduced 0 Fixed 0.75.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @opentelemetry/exporter-prometheus | 0 | 0.217.0 |
| npm | @opentelemetry/sdk-node | 0 | 0.217.0 |
| npm | @opentelemetry/auto-instrumentations-node | 0 | 0.75.0 |
Remediation
Red Hat statement
This flaw is rated as Important. A remote attacker can trigger a Denial of Service by sending a malformed HTTP request to the OpenTelemetry JS Prometheus exporter's metrics endpoint, causing the Node.js process to terminate. This impacts Red Hat products that deploy the affected exporter, leading to service disruption.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-44902 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2482216 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-32538 Advisory
- https://github.com/advisories/GHSA-q7rr-3cgh-j5r3 Advisory
- https://github.com/open-telemetry/opentelemetry-js/security/advisories/GHSA-q7rr-3cgh-j5r3 exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-44902
- https://www.cve.org/CVERecord?id=CVE-2026-44902
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-44902 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2482216 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-32538 | Advisory | |
| https://github.com/advisories/GHSA-q7rr-3cgh-j5r3 | Advisory | |
| https://github.com/open-telemetry/opentelemetry-js/security/advisories/GHSA-q7rr-3cgh-j5r3 | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-44902 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-44902 |
Change history (0)
No recorded changes yet.