Vulnerabilities/

Prometheus exporter process crash via malformed HTTP request - @opentelemetry/sdk-node

Severity:
High

Description

A single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid URI causes an uncaught TypeError that terminates the process.

Recommendation

Update the @opentelemetry/sdk-node package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@opentelemetry/sdk-node
Anything's wrong? Let us know Last updated on May 11, 2026