SCA: security update for OpenTelemetry.Exporter.OneCollector (GHSA-55m9-299j-53c7)

medium Tenable Self-Hosted Container Security Plugin ID 441006

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end
over HTTP. In versions 1.15.0 and earlier, when a request to the configured back-end or collector results
in an unsuccessful HTTP 4xx or 5xx response, the HttpJsonPostTransport class reads the entire response
body into memory with no upper bound on the number of bytes consumed in order to include the error
response in operator logs. An attacker who controls the configured endpoint, or who can intercept traffic
to it via a man-in-the-middle attack, can return an arbitrarily large response body. This causes unbounded
heap allocation in the consuming process, leading to high transient memory pressure, garbage-collection
stalls, or an OutOfMemoryException that terminates the process. As a workaround, use network-level
controls such as firewall rules, mTLS, or a service mesh to prevent man-in-the-middle attacks on the
configured back-end or collector endpoint. This issue is fixed in version 1.15.1, which limits the number
of bytes read from the response body in an error condition to 4 MiB. (CVE-2026-41484)

Solution

Update the OpenTelemetry.Exporter.OneCollector library and its related packages to version 1.15.1 or later.

See Also

https://github.com/advisories/GHSA-55m9-299j-53c7

Plugin Details

Severity: Medium

ID: 441006

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 4/30/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-41484

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/29/2026

Vulnerability Publication Date: 4/29/2026

Reference Information

CVE: CVE-2026-41484

cwe: CWE-770