<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 17:08:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-308974</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308974</link>
      <description>EUVD-2026-308974</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308974</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41310</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41310</link>
      <description>&lt;p&gt;OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cache accepts unbounded key growth derived from span attributes. In high-cardinality scenarios, a process using Zipkin export for client or producer spans could experience avoidable memory growth under sustained unique remote endpoint values, increasing process memory usage over time and degrading availability. This issue is fixed in version 1.15.3, which introduces a bounded, thread-safe LRU cache for remote endpoints with a fixed maximum size.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cache accepts unbounded key growth derived from span attributes. In high-cardinality scenarios, a process using Zipkin export for client or producer spans could experience avoidable memory growth under sustained unique remote endpoint values, increasing process memory usage over time and degrading availability. This issue is fixed in version 1.15.3, which introduces a bounded, thread-safe LRU cache for remote endpoints with a fixed maximum size.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41310</guid>
    </item>
    <item>
      <title>GHSA-88hf-wf7h-7w4m — OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-88hf-wf7h-7w4m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: OpenTelemetry.Exporter.Zipkin&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Zipkin exporter remote endpoint cache accepted unbounded key growth derived from span attributes. In high-cardinality scenarios, this could increase process memory usage over time and degrade availability.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;- Introduce a bounded, thread-safe LRU cache for remote endpoints.
- Enforce fixed maximum size to prevent unbounded growth.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- A process using Zipkin export for client/producer spans could experience avoidable memory growth under sustained unique remote endpoint values.&lt;/p&gt;
&lt;p&gt;### Resources&lt;/p&gt;
&lt;p&gt;[#7081](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7081)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: OpenTelemetry.Exporter.Zipkin&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Zipkin exporter remote endpoint cache accepted unbounded key growth derived from span attributes. In high-cardinality scenarios, this could increase process memory usage over time and degrade availability.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;- Introduce a bounded, thread-safe LRU cache for remote endpoints.
- Enforce fixed maximum size to prevent unbounded growth.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- A process using Zipkin export for client/producer spans could experience avoidable memory growth under sustained unique remote endpoint values.&lt;/p&gt;
&lt;p&gt;### Resources&lt;/p&gt;
&lt;p&gt;[#7081](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7081)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-88hf-wf7h-7w4m</guid>
    </item>
  </channel>
</rss>
