Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-29181

Опубликовано: 07 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:go:*:*
Версия от 1.36.0 (включая) до 1.41.0 (исключая)

EPSS

Процентиль: 44%
0.00572
Низкий

7.5 High

CVSS3

Дефекты

CWE-770
CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

CVSS3: 7.5
redhat
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

CVSS3: 7.5
msrc
3 месяца назад

OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

CVSS3: 7.5
debian
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36. ...

CVSS3: 7.5
github
4 месяца назад

OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

EPSS

Процентиль: 44%
0.00572
Низкий

7.5 High

CVSS3

Дефекты

CWE-770
CWE-770