Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-29181

Опубликовано: 29 апр. 2026
Источник: msrc
CVSS3: 7.5
EPSS Низкий

Описание

OpenTelemetry-Go multi-value baggage header extraction causes excessive allocations (remote dos amplification)

EPSS

Процентиль: 44%
0.00572
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

CVSS3: 7.5
redhat
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

CVSS3: 7.5
nvd
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

CVSS3: 7.5
debian
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36. ...

CVSS3: 7.5
github
4 месяца назад

OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

EPSS

Процентиль: 44%
0.00572
Низкий

7.5 High

CVSS3