{"id":"CVE-2026-44902","aliases":["GHSA-q7rr-3cgh-j5r3"],"url":"https://o3.security/vulnerability/CVE-2026-44902","summary":"opentelemetry-js: Prometheus exporter process crash via malformed HTTP request","details":"## Summary\n\nA single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default `0.0.0.0:9464`) has no error handling around URL parsing, so a request with an invalid URI causes an uncaught `TypeError` that terminates the process.\n\n**You are affected by this vulnerability if either of the following apply to your application:**\n\n* you directly use `@opentelemetry/exporter-prometheus` in your code through its built-in server.\n* your `OTEL_METRICS_EXPORTER` environment variable includes `prometheus` **AND**\n  * you use `@opentelemetry/sdk-node`\n  * you use  `@opentelemetry/auto-instrumentations-node` via `--require @opentelemetry/auto-instrumentations-node/register`/`--import @opentelemetry/auto-instrumentations-node/register`\n\n## Impact\n\n**Denial of service.** Any application using the OpenTelemetry Prometheus exporter’s built-in server can be crashed by a single unauthenticated network packet sent to the metrics port. No authentication, special privileges, or prior access is required.\n\n## Remediation\n\n### Update to the fixed version\n\nUpdate `@opentelemetry/exporter-prometheus` and `@opentelemetry/sdk-node` to version **0.217.0** or later. \nUpdate `@opentelemetry/auto-instrumentations-node` to version **0.75.0** or later.\n\nThis release adds proper error handling around the URL constructor, returning an HTTP `400` response on parse failure rather than allowing the exception to propagate and crash the process.\n\n```\nnpm install @opentelemetry/exporter-prometheus@latest\n```\n\n### Do Not Expose the Endpoint to Untrusted Users\n\n> [!IMPORTANT] \n> The following mitigations reduce exposure but do not fully remediate the vulnerability. Any client that *can* reach the metrics endpoint - including your own Prometheus scraper host if compromised - could still trigger the crash. Updating to **0.217.0** is the recommended resolution.\n\nIf updating is not immediately feasible, restrict access to the metrics endpoint so that it is not reachable by untrusted or unauthenticated network clients. For example:\n\n* **Bind to localhost only** by setting the `host` option to `127.0.0.1` when configuring the `PrometheusExporter`, so the port is not exposed on public or shared network interfaces\n\n* **Use a firewall or network policy** to restrict access to port `9464` (or whichever port you have configured) to only trusted Prometheus scrape hosts\n\n* **Place the endpoint behind a reverse proxy** that filters or validates incoming requests before they reach the exporter\n\n## Details\n\nIn `PrometheusExporter.ts`, the `_requestHandler` calls `new URL(request.url, this._baseUrl)` without any error handling. Node's HTTP parser accepts absolute-form URIs (e.g. `http://`) for proxy compatibility, including malformed ones. When `request.url` is `\"http://\"`, the `URL` constructor throws `TypeError: Invalid URL`. Since there is no try-catch in the handler, the exception propagates as an uncaught exception and crashes the process.\n\nThe Prometheus metrics endpoint is unauthenticated by design (Prometheus scrapes it) and binds to `0.0.0.0` by default, meaning it is reachable by any network client that can connect to the metrics port.\n\n## Proof of Concept\n\nStart any Node.js application with the Prometheus exporter running on the default port `9464`, then send a single raw TCP packet:\n\n```\necho -ne 'GET http:// HTTP/1.1\\r\\nHost: localhost\\r\\n\\r\\n' | nc localhost 9464\n```\n\nThe process crashes immediately with:\n\n```\nTypeError: Invalid URL\n    at new URL (...)\n    at PrometheusExporter._requestHandler (...)\n```","published":"2026-05-27T14:49:04.940Z","modified":"2026-08-28T03:46:57.977252940Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00455,"percentile":0.37533,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@opentelemetry/exporter-prometheus","fixedVersion":"0.217.0"},{"ecosystem":"npm","name":"@opentelemetry/sdk-node","fixedVersion":"0.217.0"},{"ecosystem":"npm","name":"@opentelemetry/auto-instrumentations-node","fixedVersion":"0.75.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44902.json"},{"type":"ADVISORY","url":"https://github.com/open-telemetry/opentelemetry-js/security/advisories/GHSA-q7rr-3cgh-j5r3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44902"},{"type":"PACKAGE","url":"https://github.com/open-telemetry/opentelemetry-js"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T03:46:57.977252940Z"}}