fix(deps): update dependency @opentelemetry/sdk-node to ^0.217.0 [security] - #1511
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Deploying node-js-server with
|
| Latest commit: |
ecc5958
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://87665579.node-js-server.pages.dev |
| Branch Preview URL: | https://renovate-npm-opentelemetry-s.node-js-server.pages.dev |
|
Tick the box to add this pull request to the merge queue (same as
|
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
August 26, 2026 23:50
5f6f30d to
41d5b62
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 2, 2026 21:30
41d5b62 to
247c5f0
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
2 times, most recently
from
September 3, 2026 15:13
e4689fc to
9d616fe
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 4, 2026 03:03
9d616fe to
8107e47
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 7, 2026 22:31
8107e47 to
8033b35
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
2 times, most recently
from
September 9, 2026 19:52
51fdaaa to
107afb6
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
2 times, most recently
from
September 10, 2026 19:44
b14e282 to
72805dd
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 11, 2026 00:55
72805dd to
7927d29
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 15, 2026 10:50
7927d29 to
4574d52
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 16, 2026 02:08
4574d52 to
d62d098
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 16, 2026 17:01
d62d098 to
e4a5cbc
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
2 times, most recently
from
September 17, 2026 20:34
af88a2d to
cf01fa0
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 18, 2026 02:00
cf01fa0 to
5d9daf7
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 18, 2026 23:17
5d9daf7 to
df310b9
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 19, 2026 02:33
df310b9 to
e3c98ec
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 23, 2026 22:58
e3c98ec to
8ba713b
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 24, 2026 05:47
8ba713b to
7fc6b48
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 25, 2026 04:30
7fc6b48 to
91e45ee
Compare
renovate
Bot
force-pushed
the
renovate/npm-opentelemetry-sdk-node-vulnerability
branch
from
September 25, 2026 17:55
91e45ee to
ecc5958
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.52.0→^0.217.0Prometheus exporter process crash via malformed HTTP request
CVE-2026-44902 / GHSA-q7rr-3cgh-j5r3
More information
Details
Summary
A single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default
0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid URI causes an uncaughtTypeErrorthat terminates the process.You are affected by this vulnerability if either of the following apply to your application:
@opentelemetry/exporter-prometheusin your code through its built-in server.OTEL_METRICS_EXPORTERenvironment variable includesprometheusAND@opentelemetry/sdk-node@opentelemetry/auto-instrumentations-nodevia--require @opentelemetry/auto-instrumentations-node/register/--import @opentelemetry/auto-instrumentations-node/registerImpact
Denial of service. Any application using the OpenTelemetry Prometheus exporter’s built-in server can be crashed by a single unauthenticated network packet sent to the metrics port. No authentication, special privileges, or prior access is required.
Remediation
Update to the fixed version
Update
@opentelemetry/exporter-prometheusand@opentelemetry/sdk-nodeto version 0.217.0 or later.Update
@opentelemetry/auto-instrumentations-nodeto version 0.75.0 or later.This release adds proper error handling around the URL constructor, returning an HTTP
400response on parse failure rather than allowing the exception to propagate and crash the process.Do Not Expose the Endpoint to Untrusted Users
If updating is not immediately feasible, restrict access to the metrics endpoint so that it is not reachable by untrusted or unauthenticated network clients. For example:
Bind to localhost only by setting the
hostoption to127.0.0.1when configuring thePrometheusExporter, so the port is not exposed on public or shared network interfacesUse a firewall or network policy to restrict access to port
9464(or whichever port you have configured) to only trusted Prometheus scrape hostsPlace the endpoint behind a reverse proxy that filters or validates incoming requests before they reach the exporter
Details
In
PrometheusExporter.ts, the_requestHandlercallsnew URL(request.url, this._baseUrl)without any error handling. Node's HTTP parser accepts absolute-form URIs (e.g.http://) for proxy compatibility, including malformed ones. Whenrequest.urlis"http://", theURLconstructor throwsTypeError: Invalid URL. Since there is no try-catch in the handler, the exception propagates as an uncaught exception and crashes the process.The Prometheus metrics endpoint is unauthenticated by design (Prometheus scrapes it) and binds to
0.0.0.0by default, meaning it is reachable by any network client that can connect to the metrics port.Proof of Concept
Start any Node.js application with the Prometheus exporter running on the default port
9464, then send a single raw TCP packet:The process crashes immediately with:
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
open-telemetry/opentelemetry-js (@opentelemetry/sdk-node)
v0.217.0Compare Source
v0.216.0Compare Source
v0.215.0Compare Source
v0.214.0Compare Source
v0.213.0Compare Source
v0.212.0Compare Source
v0.211.0Compare Source
v0.210.0Compare Source
v0.209.0Compare Source
v0.208.0Compare Source
v0.207.0Compare Source
v0.206.0Compare Source
v0.205.0Compare Source
v0.204.0Compare Source
v0.203.0Compare Source
v0.202.0Compare Source
v0.201.1Compare Source
v0.201.0Compare Source
v0.200.0Compare Source
v0.57.2Compare Source
v0.57.1Compare Source
v0.57.0Compare Source
v0.56.0Compare Source
v0.55.0Compare Source
v0.54.2Compare Source
v0.54.1Compare Source
v0.54.0Compare Source
v0.53.0Compare Source
v0.52.1Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.