Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39882

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 7.5

Описание

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can mitm the exporter connection). This vulnerability is fixed in 1.43.0.

A flaw was found in OpenTelemetry-Go. The otlp HTTP exporters read the full HTTP response body into an in-memory buffer without a size cap. A remote attacker, by controlling the collector endpoint or performing a man-in-the-middle (MITM) attack on the exporter connection, can exploit this to cause memory exhaustion. This vulnerability can lead to a Denial of Service (DoS) for the affected system.

Отчет

This Important flaw in OpenTelemetry-Go's OTLP HTTP exporters can lead to a denial of service in Red Hat products, such as OpenShift Container Platform and Multicluster Engine for Kubernetes, that utilize OpenTelemetry-Go for telemetry collection. The vulnerability arises from the exporters reading HTTP response bodies into an unbounded in-memory buffer, allowing a remote attacker to exhaust system memory if they control the collector endpoint or perform a Man-in-the-Middle attack on the connection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/maestro-rhel9Under investigation
Red Hat OpenShift Container Platform 4.22openshift4/ose-thanos-rhel9FixedRHSA-2026:3758514.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2456727github.com/open-telemetry/opentelemetry-go: golang: OpenTelemetry-Go: Memory exhaustion via uncapped HTTP response body reading

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can mitm the exporter connection). This vulnerability is fixed in 1.43.0.

CVSS3: 5.3
nvd
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can mitm the exporter connection). This vulnerability is fixed in 1.43.0.

CVSS3: 5.3
msrc
4 месяца назад

OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies

CVSS3: 5.3
debian
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1 ...

CVSS3: 5.3
github
4 месяца назад

opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies

7.5 High

CVSS3