High [CVE-2026-59892] @opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of Service via malformed HTTP header decoding
This high-severity Red Hat Linux advisory covers CVE-2026-59892 affecting Red Hat Developer Hub 1.10, Red Hat Developer Hub 1.9, OpenShift Serverless.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
OpenTelemetry JavaScript is the OpenTelemetry JavaScript client.
Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed percent-encoded value that throws an uncaught URIError and terminates a Node.js process using JaegerPropagator as the active propagator.
This issue is fixed in version 2.9.0. Successful exploitation of this flaw can terminate a Node.js process, resulting in a Denial of Service (DoS).
This flaw affects the @opentelemetry/propagator-jaeger package used by container images that configure the Jaeger trace-context propagator. Red Hat CVSS score (7.5, Important) is consistent with upstream and NVD scoring.
Weakness: CWE-248. Affected Red Hat products: Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9; OpenShift Serverless; Self-service automation portal 2.
Red Hat fixing advisory: RHSA-2026:49642, RHSA-2026:52768.
- < 2.9.0
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
- 2.9.0
- rhdh/rhdh-hub-rhel9:1785411652
- rhdh/rhdh-hub-rhel9:1785972843
- RHSA-2026:49642
- RHSA-2026:52768
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Mitigation checklist
- Administrators can mitigate this issue by not configuring JaegerPropagator as the active OpenTelemetry propagator (use W3C Trace Context or B3 propagation instead), or by deploying an ingress/proxy in front of the affected service that validates or strips uber-trace-id and uberctx-* headers before they reach the application. Upgrading to @opentelemetry/propagator-jaeger >= 2.9.0 resolves the issue upstream.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.