Skip to content
VulniPulse
High7.5Red Hat Linux

High [CVE-2026-59892] @opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of Service via malformed HTTP header decoding

This high-severity Red Hat Linux advisory covers CVE-2026-59892 affecting Red Hat Developer Hub 1.10, Red Hat Developer Hub 1.9, OpenShift Serverless.

CVE-2026-59892 Published Jul 8, 2026Updated by vendor Jul 8, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

OpenTelemetry JavaScript is the OpenTelemetry JavaScript client.

Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed percent-encoded value that throws an uncaught URIError and terminates a Node.js process using JaegerPropagator as the active propagator.

This issue is fixed in version 2.9.0. Successful exploitation of this flaw can terminate a Node.js process, resulting in a Denial of Service (DoS).

This flaw affects the @opentelemetry/propagator-jaeger package used by container images that configure the Jaeger trace-context propagator. Red Hat CVSS score (7.5, Important) is consistent with upstream and NVD scoring.

Weakness: CWE-248. Affected Red Hat products: Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9; OpenShift Serverless; Self-service automation portal 2.

Red Hat fixing advisory: RHSA-2026:49642, RHSA-2026:52768.

Affected versions
  • < 2.9.0

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Fixed versions
  • 2.9.0
  • rhdh/rhdh-hub-rhel9:1785411652
  • rhdh/rhdh-hub-rhel9:1785972843
  • RHSA-2026:49642
  • RHSA-2026:52768

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Administrators can mitigate this issue by not configuring JaegerPropagator as the active OpenTelemetry propagator (use W3C Trace Context or B3 propagation instead), or by deploying an ingress/proxy in front of the affected service that validates or strips uber-trace-id and uberctx-* headers before they reach the application. Upgrading to @opentelemetry/propagator-jaeger >= 2.9.0 resolves the issue upstream.

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.