GHSA-88hf-wf7h-7w4m
OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure
Quick fix
GHSA-88hf-wf7h-7w4m — OpenTelemetry.Exporter.Zipkin: upgrade to the fixed version with the command below.
dotnet add package OpenTelemetry.Exporter.Zipkin --version 1.15.3Details
### Summary
The Zipkin exporter remote endpoint cache accepted unbounded key growth derived from span attributes. In high-cardinality scenarios, this could increase process memory usage over time and degrade availability.
### Details
- Introduce a bounded, thread-safe LRU cache for remote endpoints. - Enforce fixed maximum size to prevent unbounded growth.
### Impact
- A process using Zipkin export for client/producer spans could experience avoidable memory growth under sustained unique remote endpoint values.
### Resources
[#7081](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7081)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.15.3dotnet add package OpenTelemetry.Exporter.Zipkin --version 1.15.3References
- https://github.com/open-telemetry/opentelemetry-dotnet/security/advisories/GHSA-88hf-wf7h-7w4m[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-41310[ADVISORY]
- https://github.com/open-telemetry/opentelemetry-dotnet/pull/7081[WEB]
- https://github.com/open-telemetry/opentelemetry-dotnet/commit/c724f4bd6fd88e9a599af1668bf7af9487155b62[WEB]
- https://github.com/open-telemetry/opentelemetry-dotnet[PACKAGE]