Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-41178

2 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-41178

2 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-41178

2 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-41178

2 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1 ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-5wrp-cwcj-q835

3 месяца назад

opentelemetry-go's baggage parsing no longer caps raw header length

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-41178

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

CVSS3: 5.3
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-41178

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-41178

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

CVSS3: 5.3
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-41178

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1 ...

CVSS3: 5.3
0%
Низкий
2 месяца назад
github логотип
GHSA-5wrp-cwcj-q835

opentelemetry-go's baggage parsing no longer caps raw header length

CVSS3: 5.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу