Описание
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.
A flaw was found in OpenTelemetry-Go, the Go implementation of OpenTelemetry. A remote attacker can exploit this vulnerability by sending multiple 'baggage' header lines. The system's independent parsing and aggregation of each header field-value across multiple values can lead to amplified CPU and memory allocations, resulting in a Denial of Service (DoS).
Отчет
This is an Important denial of service vulnerability in OpenTelemetry-Go, affecting Red Hat Multicluster Engine for Kubernetes. A remote attacker can exploit this flaw by sending multiple crafted baggage HTTP header lines, leading to excessive CPU and memory consumption and potentially rendering services unavailable. This impact is significant due to the potential for widespread disruption in a multi-cluster environment.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-service-9-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/managedcluster-import-controller-rhel9 | Affected | ||
| Multicluster Engine for Kubernetes | multicluster-engine/multicloud-manager-rhel9 | Affected | ||
| Multicluster Engine for Kubernetes | multicluster-engine/placement-rhel9 | Affected | ||
| Multicluster Engine for Kubernetes | multicluster-engine/registration-operator-rhel9 | Affected | ||
| Multicluster Engine for Kubernetes | multicluster-engine/registration-rhel9 | Affected | ||
| Multicluster Engine for Kubernetes | multicluster-engine/work-rhel9 | Affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/multicluster-observability-rhel9-operator | Under investigation | ||
| multicluster engine for Kubernetes 2.11 | multicluster-engine/hypershift-addon-rhel9-operator | Fixed | RHSA-2026:25271 | 11.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.
OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36. ...
OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
EPSS
7.5 High
CVSS3