Back

HIGH

opentelemetry-js: Prometheus exporter process crash via malformed HTTP request

Published May 27, 2026

Description

opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid URI causes an uncaught TypeError that terminates the process. This vulnerability is fixed in 0.217.0.

Affected products

Remediation

Red Hat statement

This flaw is rated as Important. A remote attacker can trigger a Denial of Service by sending a malformed HTTP request to the OpenTelemetry JS Prometheus exporter's metrics endpoint, causing the Node.js process to terminate. This impacts Red Hat products that deploy the affected exporter, leading to service disruption.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 27, 2026
Updated May 28, 2026
Reserved May 7, 2026
CISA Vulnrichment
Updated May 28, 2026
NVD
Status Analyzed
Modified Aug 27, 2026
Red Hat
Severity Important
Public date May 27, 2026
ENISA EUVD
Assigner GitHub_M
Published May 27, 2026
Updated May 28, 2026
Exploited since n/a
EUVD-2026-32538 GHSA-Q7RR-3CGH-J5R3