VDB
Sign up
MEDIUM5.3

GHSA-88hf-wf7h-7w4m

OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure

Quick fix

GHSA-88hf-wf7h-7w4m — OpenTelemetry.Exporter.Zipkin: upgrade to the fixed version with the command below.

dotnet add package OpenTelemetry.Exporter.Zipkin --version 1.15.3

Details

### Summary

The Zipkin exporter remote endpoint cache accepted unbounded key growth derived from span attributes. In high-cardinality scenarios, this could increase process memory usage over time and degrade availability.

### Details

- Introduce a bounded, thread-safe LRU cache for remote endpoints. - Enforce fixed maximum size to prevent unbounded growth.

### Impact

- A process using Zipkin export for client/producer spans could experience avoidable memory growth under sustained unique remote endpoint values.

### Resources

[#7081](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7081)

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/OpenTelemetry.Exporter.Zipkin
Introduced in: 0Fixed in: 1.15.3
Fixdotnet add package OpenTelemetry.Exporter.Zipkin --version 1.15.3

References