Skip to main content
Version: v1.2.x

CVE-2026-41178

CVE Details

Visit the official vulnerability details page for CVE-2026-41178 to learn more.

Initial Publication

06/04/2026

Last Update

07/22/2026

Third Party Dependency

go.opentelemetry.io/otel

NIST CVE Summary

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

CVE Severity

5.3

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Analyzed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.2.0⚠️ Impacted⚠️ Impacted
1.1.8⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.