Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q7rr-3cgh-j5r3 | Prometheus exporter process crash via malformed HTTP request |
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opentelemetry
Opentelemetry auto-instrumentations-node Opentelemetry exporter-prometheus Opentelemetry opentelemetry-js Opentelemetry sdk-node |
|
| Vendors & Products |
Opentelemetry
Opentelemetry auto-instrumentations-node Opentelemetry exporter-prometheus Opentelemetry opentelemetry-js Opentelemetry sdk-node |
Thu, 28 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid URI causes an uncaught TypeError that terminates the process. This vulnerability is fixed in 0.217.0. | |
| Title | opentelemetry-js: Prometheus exporter process crash via malformed HTTP request | |
| Weaknesses | CWE-755 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-28T15:26:13.701Z
Reserved: 2026-05-07T21:50:33.547Z
Link: CVE-2026-44902
Updated: 2026-05-28T15:25:57.484Z
Status : Awaiting Analysis
Published: 2026-05-27T15:16:29.313
Modified: 2026-06-17T10:51:30.497
Link: CVE-2026-44902
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:21:46Z
Github GHSA