Vulnerability Description
The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sending telemetry to a configured Instana back-end when a proxy is configured using the INSTANA_ENDPOINT_PROXY environment variable. If a network attacker can Man-in-the-Middle (MitM) the proxy connection, all OpenTelemetry telemetry data and the Instana API key are exposed to the attacker. This vulnerability is fixed in 1.1.0.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisori
- https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisori
FAQ
What is CVE-2026-44213?
CVE-2026-44213 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sendin...
How severe is CVE-2026-44213?
CVE-2026-44213 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44213?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.