CVE-2026-59892: OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
Summary
@opentelemetry/propagator-jaeger decodes incoming HTTP header values with decodeURIComponent() without handling decode errors. A single request carrying a malformed percent-encoded value (for example a bare %) in an uber-trace-id or uberctx- header throws an uncaught URIError, terminating any Node.js process that uses JaegerPropagator as its active propagator.
Impact
Denial of Service: Any unauthenticated remote attacker who can send an HTTP request to a service that has JaegerPropagator registered as the global propagator (e.g. via OTELPROPAGATORS=jaeger or propagation.setGlobalPropagator(new JaegerPropagator())) can terminate the process with a single request. Confidentiality and integrity are not affected.
Am I affected?
This issue affects only a specific, opt-in configuration. If you use OpenTelemetry's default propagators (W3C TraceContext and Baggage), you are not affected.
You are affected only if you have registered JaegerPropagator as the active propagator. Check for:
- @opentelemetry/propagator-jaeger in your dependency tree, and - OTELPROPAGATORS set to jaeger (Jaeger only), or a direct propagation.setGlobalPropagator(new JaegerPropagator()) call in your code.
Note: if JaegerPropagator is combined with other propagators through a CompositePropagator (for example OTELPROPAGATORS=jaeger,tracecontext), the process does not terminate - the composite propagator catches the error - but affected requests silently fail to extract context. You should still upgrade.
Patched versions
- @opentelemetry/propagator-jaeger 2.9.0
Remediation
Update @opentelemetry/propagator-jaeger to 2.9.0 or later. The propagator now ignores header values it cannot decode instead of throwing.
Interim mitigation (if you cannot update): Trace-context headers should never be accepted unfiltered from untrusted callers. Until you can upgrade, strip or validate the uber-trace-id and uberctx- headers on inbound requests at your edge - for example with a reverse proxy, API gateway, or load balancer (nginx, Envoy, etc.) - so that only trusted upstream services can set them.
Details
JaegerPropagator.extract() calls decodeURIComponent() on raw header values at two unguarded call sites: the uber-trace-id trace header and each uberctx- baggage value. decodeURIComponent() throws URIError: URI malformed on invalid percent-encoding. Because the HTTP instrumentation extracts context before its request-handler error wrapper, and a single configured propagator is not wrapped in a CompositePropagator (which would otherwise catch the error), the exception propagates as an uncaughtException and terminates the process.
Proof of concept
Against a service using JaegerPropagator:
bash curl -H 'uberctx-user: %' http://target/ or curl -H 'uber-trace-id: %' http://target/
The Node.js process exits with URIError: URI malformed and subsequent requests are refused.
Other sources
OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx- HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed percent-encoded value that throws an uncaught URIError and terminates a Node.js process using JaegerPropagator as the active propagator. This issue is fixed in version 2.9.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@opentelemetry/propagator-jaegerto a version that resolves this vulnerability.Fixed in 2.9.0 - Upgrade
Upgrade
@opentelemetry/propagator-jaegerto a version that resolves this vulnerability.Fixed in 2.9.0 - Compensating control
Interim mitigation: strip or validate inbound `uber-trace-id` and `uberctx-*` HTTP headers at your edge (reverse proxy/API gateway/load balancer, e.g., nginx/Envoy) so only trusted upstream services can set them.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59892?
The severity of CVE-2026-59892 is high, rated at 7.5.
What does CVE-2026-59892 affect?
CVE-2026-59892 affects the OpenTelemetry JavaScript client, specifically the JaegerPropagator.
How do I fix CVE-2026-59892?
To fix CVE-2026-59892, update the OpenTelemetry JavaScript to version 2.9.0 or later.
What type of vulnerability is CVE-2026-59892?
CVE-2026-59892 is a Denial of Service vulnerability caused by unhandled exceptions on malformed headers.
Who can exploit CVE-2026-59892?
CVE-2026-59892 can be exploited by an unauthenticated remote attacker.