Vulnerability GO-2026-4985
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 months ago
May 26, 2026 at 10:48 PM UTC
Oversized OTLP HTTP response bodies can cause memory exhaustion in go.opentelemetry.io/otel/exporters/otlp
v0.2.0-alpha - v0.18.0
v0.2.0-alpha - v0.18.0
Summary
Oversized OTLP HTTP response bodies can cause memory exhaustion in go.opentelemetry.io/otel/exporters/otlp
Details
The OTLP HTTP exporters (traces, metrics, and logs) do not limit the size of the HTTP response body read from the collector. A malicious or misconfigured collector can send a large response body, leading to excessive memory consumption and potential process termination (OOM).
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
13 days ago
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
v1.5.0 - v1.44.0 GHSA-8wmf-6v46-5gfg
v1.5.0 - v1.44.0 GHSA-8wmf-6v46-5gfg
Medium Risk
5 months ago
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
v1.0.0-RC1 - v1.42.0 GHSA-w8rr-5gcm-pp58
v1.0.0-RC1 - v1.42.0 GHSA-w8rr-5gcm-pp58
Medium Risk
5 months ago
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
v1.0.0-RC1 - v1.42.0 GHSA-w8rr-5gcm-pp58
v1.0.0-RC1 - v1.42.0 GHSA-w8rr-5gcm-pp58
Medium Risk
5 months ago
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
v1.0.0-RC1 - v1.42.0 GHSA-w8rr-5gcm-pp58
v1.0.0-RC1 - v1.42.0 GHSA-w8rr-5gcm-pp58
Impacted packages
Timeline
Published
4 months ago
May 26, 2026 at 10:48 PM UTC
Last Modified
4 months ago
May 27, 2026 at 02:44 PM UTC