Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29181

Опубликовано: 07 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

A flaw was found in OpenTelemetry-Go, the Go implementation of OpenTelemetry. A remote attacker can exploit this vulnerability by sending multiple 'baggage' header lines. The system's independent parsing and aggregation of each header field-value across multiple values can lead to amplified CPU and memory allocations, resulting in a Denial of Service (DoS).

Отчет

This is an Important denial of service vulnerability in OpenTelemetry-Go, affecting Red Hat Multicluster Engine for Kubernetes. A remote attacker can exploit this flaw by sending multiple crafted baggage HTTP header lines, leading to excessive CPU and memory consumption and potentially rendering services unavailable. This impact is significant due to the potential for widespread disruption in a multi-cluster environment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/managedcluster-import-controller-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/multicloud-manager-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/placement-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/registration-operator-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/registration-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/work-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-observability-rhel9-operatorUnder investigation
multicluster engine for Kubernetes 2.11multicluster-engine/hypershift-addon-rhel9-operatorFixedRHSA-2026:2527111.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2456252github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Denial of Service via crafted multi-value baggage headers

EPSS

Процентиль: 42%
0.00533
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

CVSS3: 7.5
nvd
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

CVSS3: 7.5
msrc
3 месяца назад

OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

CVSS3: 7.5
debian
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36. ...

CVSS3: 7.5
github
4 месяца назад

OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

EPSS

Процентиль: 42%
0.00533
Низкий

7.5 High

CVSS3