{"id":"CVE-2025-27513","aliases":["GHSA-8785-wc3w-h8q6"],"url":"https://o3.security/vulnerability/CVE-2025-27513","summary":"OpenTelemetry .NET has a Denial of Service (DoS) Vulnerability in API Package","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nA vulnerability in `OpenTelemetry.Api` package `1.10.0` to `1.11.1` could cause a Denial of Service (DoS) when a `tracestate` and `traceparent` header is received.\n\n* Even if an application does not explicitly use trace context propagation, receiving these headers can still trigger high CPU usage.\n* This issue impacts any application accessible over the web or backend services that process HTTP requests containing a `tracestate` header.\n* Application may experience excessive resource consumption, leading to increased latency, degraded performance, or downtime.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nThis issue has been <strong data-start=\"1143\" data-end=\"1184\">resolved in OpenTelemetry.Api 1.11.2</strong> by <strong data-start=\"1188\" data-end=\"1212\">reverting the change</strong> that introduced the problematic behavior in versions <strong data-start=\"1266\" data-end=\"1286\">1.10.0 to 1.11.1</strong>.</li><li data-start=\"1290\" data-end=\"1409\">The fix ensures that <strong data-start=\"1313\" data-end=\"1380\">valid tracing headers no longer cause excessive CPU consumption</strong> when received in requests.</li></ul><h4 data-start=\"1411\" data-end=\"1434\"><strong data-start=\"1416\" data-end=\"1434\">Fixed Version:</strong></h4>\nOpenTelemetry .NET Version | Status\n-- | --\n<= 1.9.x | ✅ Not affected\n1.10.0 - 1.11.1 | ❌ Vulnerable\n1.11.2 (Fixed) | ✅ Safe to use\n\n**Upgrade Command:**\n\n```\ndotnet add package OpenTelemetry --version 1.11.2\n```\n\n**Delisting of Affected Packages**\nTo prevent accidental usage, we have delisted the affected versions (1.10.0 to 1.11.1) from NuGet. Users should avoid these versions and upgrade to 1.11.2 immediately.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\n### References\n_Are there any links users can visit to find out more?_","published":"2025-03-05T18:12:25.867Z","modified":"2026-08-12T03:51:46.886772736Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00489,"percentile":0.39821,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"OpenTelemetry.Api","fixedVersion":"1.11.2"},{"ecosystem":"NuGet","name":"OpenTelemetry.Api","fixedVersion":null},{"ecosystem":"NuGet","name":"OpenTelemetry.Api","fixedVersion":null},{"ecosystem":"NuGet","name":"OpenTelemetry.Api","fixedVersion":null},{"ecosystem":"NuGet","name":"OpenTelemetry.Api","fixedVersion":null}],"fix":{"url":"https://github.com/open-telemetry/opentelemetry-dotnet/commit/1b555c1201413f2f55f2cd3c4ba03ef4b615b6b5","label":"open-telemetry/opentelemetry-dotnet@1b555c1"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27513.json"},{"type":"ADVISORY","url":"https://github.com/open-telemetry/opentelemetry-dotnet/security/advisories/GHSA-8785-wc3w-h8q6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27513"},{"type":"FIX","url":"https://github.com/open-telemetry/opentelemetry-dotnet/commit/1b555c1201413f2f55f2cd3c4ba03ef4b615b6b5"},{"type":"WEB","url":"https://github.com/open-telemetry/opentelemetry-dotnet/pull/6161"},{"type":"PACKAGE","url":"https://github.com/open-telemetry/opentelemetry-dotnet"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.886772736Z"}}