Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-41178

Опубликовано: 04 июн. 2026
Источник: debian
EPSS Низкий

Описание

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-opentelemetry-otelunfixedpackage
golang-opentelemetry-otelno-dsatrixiepackage
golang-opentelemetry-otelno-dsabookwormpackage

Примечания

  • https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835

  • https://github.com/open-telemetry/opentelemetry-go/pull/7880

EPSS

Процентиль: 15%
0.00237
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

CVSS3: 7.5
redhat
2 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

CVSS3: 5.3
nvd
2 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

CVSS3: 5.3
github
3 месяца назад

opentelemetry-go's baggage parsing no longer caps raw header length

EPSS

Процентиль: 15%
0.00237
Низкий