OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can mitm the exporter connection). This vulnerability is fixed in 1.43.0.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade dockerUpgrade containerd-debuginfoUpgrade containerdUpgrade docker-debuginfoUpgrade containerd-stressUpgrade amazon-cloudwatch-agent | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade dockerUpgrade docker-debugsourceUpgrade docker-debuginfo | May 19, 2026 | Apr 8, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.4.13Upgrade Splunk Enterprise to version 10.2.5Upgrade Splunk Enterprise to version 10.0.8Upgrade Splunk Enterprise to version 10.4.1 | Jul 30, 2026 | Apr 8, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub