Update npm package @opentelemetry/sdk-node to v0.217.0 [SECURITY]#8739
Update npm package @opentelemetry/sdk-node to v0.217.0 [SECURITY]#8739hash-worker[bot] wants to merge 1 commit into
@opentelemetry/sdk-node to v0.217.0 [SECURITY]#8739Conversation
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
2 Skipped Deployments
|
PR SummaryLow Risk Overview Reviewed by Cursor Bugbot for commit e28affb. Bugbot is set up for automated code reviews on this repo. Configure here. |
🤖 Augment PR SummarySummary: Updates the load-test package to use Why: Picks up the security fix called out in the GitHub advisory (CVE-2026-44902) for Prometheus exporter URL parsing crash scenarios. 🤖 Was this summary useful? React with 👍 or 👎 |
| "@opentelemetry/exporter-trace-otlp-grpc": "0.207.0", | ||
| "@opentelemetry/resources": "2.2.0", | ||
| "@opentelemetry/sdk-node": "0.207.0", | ||
| "@opentelemetry/sdk-node": "0.217.0", |
There was a problem hiding this comment.
tests/hash-backend-load/package.json:41 — This bumps @opentelemetry/sdk-node to 0.217.0 while @opentelemetry/exporter-trace-otlp-grpc remains at 0.207.0; since these 0.x OpenTelemetry packages tend to be version-aligned, this can result in duplicate/mismatched internal OTel dependencies and subtle runtime issues. Consider aligning the OpenTelemetry experimental package versions (or double-checking peer/interop compatibility for this combo).
Severity: medium
🤖 Was this useful? React with 👍 or 👎, or 🚀 if it prevented an incident/outage.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit e28affb. Configure here.
| "@opentelemetry/exporter-trace-otlp-grpc": "0.207.0", | ||
| "@opentelemetry/resources": "2.2.0", | ||
| "@opentelemetry/sdk-node": "0.207.0", | ||
| "@opentelemetry/sdk-node": "0.217.0", |
There was a problem hiding this comment.
OpenTelemetry experimental packages version mismatch after partial upgrade
Medium Severity
@opentelemetry/sdk-node is bumped to 0.217.0 while @opentelemetry/exporter-trace-otlp-grpc remains at 0.207.0. These are experimental packages from the same monorepo released in lockstep and intended to be used at matching versions. The 10-version gap can cause duplicate internal dependency instances (e.g., @opentelemetry/resources at both 2.2.0 and ~2.7.x), potentially breaking context propagation or resource merging in the tracing setup.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit e28affb. Configure here.


This PR contains the following updates:
0.207.0→0.217.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
GitHub Vulnerability Alerts
CVE-2026-44902
Summary
A single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default
0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid URI causes an uncaughtTypeErrorthat terminates the process.You are affected by this vulnerability if either of the following apply to your application:
@opentelemetry/exporter-prometheusin your code through its built-in server.OTEL_METRICS_EXPORTERenvironment variable includesprometheusAND@opentelemetry/sdk-node@opentelemetry/auto-instrumentations-nodevia--require @​opentelemetry/auto-instrumentations-node/register/--import @​opentelemetry/auto-instrumentations-node/registerImpact
Denial of service. Any application using the OpenTelemetry Prometheus exporter’s built-in server can be crashed by a single unauthenticated network packet sent to the metrics port. No authentication, special privileges, or prior access is required.
Remediation
Update to the fixed version
Update
@opentelemetry/exporter-prometheusand@opentelemetry/sdk-nodeto version 0.217.0 or later.Update
@opentelemetry/auto-instrumentations-nodeto version 0.75.0 or later.This release adds proper error handling around the URL constructor, returning an HTTP
400response on parse failure rather than allowing the exception to propagate and crash the process.Do Not Expose the Endpoint to Untrusted Users
Important
The following mitigations reduce exposure but do not fully remediate the vulnerability. Any client that can reach the metrics endpoint - including your own Prometheus scraper host if compromised - could still trigger the crash. Updating to 0.217.0 is the recommended resolution.
If updating is not immediately feasible, restrict access to the metrics endpoint so that it is not reachable by untrusted or unauthenticated network clients. For example:
Bind to localhost only by setting the
hostoption to127.0.0.1when configuring thePrometheusExporter, so the port is not exposed on public or shared network interfacesUse a firewall or network policy to restrict access to port
9464(or whichever port you have configured) to only trusted Prometheus scrape hostsPlace the endpoint behind a reverse proxy that filters or validates incoming requests before they reach the exporter
Details
In
PrometheusExporter.ts, the_requestHandlercallsnew URL(request.url, this._baseUrl)without any error handling. Node's HTTP parser accepts absolute-form URIs (e.g.http://) for proxy compatibility, including malformed ones. Whenrequest.urlis"http://", theURLconstructor throwsTypeError: Invalid URL. Since there is no try-catch in the handler, the exception propagates as an uncaught exception and crashes the process.The Prometheus metrics endpoint is unauthenticated by design (Prometheus scrapes it) and binds to
0.0.0.0by default, meaning it is reachable by any network client that can connect to the metrics port.Proof of Concept
Start any Node.js application with the Prometheus exporter running on the default port
9464, then send a single raw TCP packet:The process crashes immediately with:
Release Notes
open-telemetry/opentelemetry-js (@opentelemetry/sdk-node)
v0.217.0Compare Source
v0.216.0Compare Source
v0.215.0Compare Source
v0.214.0Compare Source
v0.213.0Compare Source
v0.212.0Compare Source
v0.211.0Compare Source
v0.210.0Compare Source
v0.209.0Compare Source
v0.208.0Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.