Security Advisory

CVE-2026-59892

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-08 16:03:58
Last updated 2026-07-08 19:41:27
Assigner GitHub_M
CVSS score 7.5
State PUBLISHED

Description

OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed percent-encoded value that throws an uncaught URIError and terminates a Node.js process using JaegerPropagator as the active propagator. This issue is fixed in version 2.9.0.