Answer in brief
CVE-2026-54712 records a Medium severity (CVSS 5.3) security vulnerability in OpenTelemetry Javaagent RMI context propagation allows resource exhaustion. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Answer in brief
CVE-2026-54712 records a Medium severity (CVSS 5.3) security vulnerability in OpenTelemetry Javaagent RMI context propagation allows resource exhaustion. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Update io.opentelemetry.javaagent:opentelemetry-javaagent to 2.27.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-54712 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| io.opentelemetry.javaagent:opentelemetry-javaagentmaven | <2.27.0 | 2.27.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-54712 records a Medium severity (CVSS 5.3) security vulnerability in OpenTelemetry Javaagent RMI context propagation allows resource exhaustion. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for io.opentelemetry.javaagent:opentelemetry-javaagent.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate io.opentelemetry.javaagent:opentelemetry-javaagent to 2.27.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-54712 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| io.opentelemetry.javaagent:opentelemetry-javaagentmaven | <2.27.0 | 2.27.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-54712 records a Medium severity (CVSS 5.3) security vulnerability in OpenTelemetry Javaagent RMI context propagation allows resource exhaustion. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for io.opentelemetry.javaagent:opentelemetry-javaagent.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardOpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, the RMI context propagation payload reader limits the number of context entries but does not limit the aggregate size of the strings read from the stream. An attacker who can reach an RMI endpoint on an instrumented JVM can send an oversized context propagation payload. This can cause excessive memory allocation while the JVM reads the payload, potentially leading to denial of service. The issue affects only deployments where RMI instrumentation is enabled and an RMI endpoint is network-reachable. This issue has been fixed in version 2.27.0.
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, the RMI context propagation payload reader limits the number of context entries but does not limit the aggregate size of the strings read from the stream. An attacker who can reach an RMI endpoint on an instrumented JVM can send an oversized context propagation payload. This can cause excessive memory allocation while the JVM reads the payload, potentially leading to denial of service. The issue affects only deployments where RMI instrumentation is enabled and an RMI endpoint is network-reachable. This issue has been fixed in version 2.27.0.