MEDIUMMaven

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

CVE-2026-54712Published 1 week agoUpdated 1 week agoSource: OSV

Affected packages

  • io.opentelemetry.javaagent:opentelemetry-javaagentbefore 2.27.0

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.26%
EPSS percentile
18.0%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 18%.

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion | HackTribune