Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-29181

Опубликовано: 07 апр. 2026
Источник: debian
EPSS Низкий

Описание

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-opentelemetry-otelnot-affectedpackage

Примечания

  • https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-mh2q-q3fh-2475

  • Introduced with: https://github.com/open-telemetry/opentelemetry-go/commit/f410084b21a46a212f6cabd37678fecc254d80f3 (v1.36.0)

EPSS

Процентиль: 44%
0.00572
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

CVSS3: 7.5
redhat
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

CVSS3: 7.5
nvd
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

CVSS3: 7.5
msrc
3 месяца назад

OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

CVSS3: 7.5
github
4 месяца назад

OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

EPSS

Процентиль: 44%
0.00572
Низкий