Vulnerability GO-2026-4985

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 months ago
May 26, 2026 at 10:48 PM UTC
Oversized OTLP HTTP response bodies can cause memory exhaustion in go.opentelemetry.io/otel/exporters/otlp
v0.2.0-alpha - v0.18.0
v0.2.0-alpha - v0.18.0

Summary

Oversized OTLP HTTP response bodies can cause memory exhaustion in go.opentelemetry.io/otel/exporters/otlp

Details

The OTLP HTTP exporters (traces, metrics, and logs) do not limit the size of the HTTP response body read from the collector. A malicious or misconfigured collector can send a large response body, leading to excessive memory consumption and potential process termination (OOM).

Timeline

Published
4 months ago
May 26, 2026 at 10:48 PM UTC
Last Modified
4 months ago
May 27, 2026 at 02:44 PM UTC