GHSA-fq3f-m5qm-99f5: OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Summary
OpenTelemetry Javaagent has a vulnerability in RMI context propagation (a feature that passes request information across RMI, which is a Java technology for calling functions on remote computers). An attacker who can reach an RMI endpoint can send an oversized payload that causes the Java Virtual Machine to allocate excessive memory, potentially crashing the service or making it unavailable. The vulnerability only affects systems that have RMI instrumentation enabled and the RMI endpoint exposed to the network.
Vulnerability Details
EPSS: 0.3%
Yes
July 29, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://github.com/advisories/GHSA-fq3f-m5qm-99f5
First tracked: July 29, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 75%