Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 NuGet

OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure

GHSA-88hf-wf7h-7w4m · CVE-2026-41310

Published · Modified

Description

Summary

The Zipkin exporter remote endpoint cache accepted unbounded key growth derived from span attributes. In high-cardinality scenarios, this could increase process memory usage over time and degrade availability.

Details

  • Introduce a bounded, thread-safe LRU cache for remote endpoints.
  • Enforce fixed maximum size to prevent unbounded growth.

Impact

  • A process using Zipkin export for client/producer spans could experience avoidable memory growth under sustained unique remote endpoint values.

Resources

#7081

Ready to move

Start Securing

Free, no credit card | First findings in minutes