← Back to CVE List
CVE-2026-81869NVD
Vulnerability Summary
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing the valid Unicode replacement character U+FFFD. safeTruncateValidUTF8 treats the valid replacement rune as invalid UTF-8 and returns the original input, while strings.ToValidUTF8 leaves that valid rune unchanged, so a second safeTruncate attempt can also return the oversized value. An attacker who controls span attribute content can retain values longer than the configured limit, increasing per-span memory use and weakening denial-of-service protection in the instrumented process. This issue is fixed in version 1.33.0.
CVSS v4.0 Base Metrics — Score 5.1 (MEDIUM)
Attack VectorLocal
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- open-telemetry opentelemetry-go >= >= 1.10.0, < 1.33.0
Not provided by cveorg for this CVE.
External References
- https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-p9f8-wvj8-2fg8
- https://github.com/open-telemetry/opentelemetry-go/issues/5996
- https://github.com/open-telemetry/opentelemetry-go/pull/5997
- https://github.com/open-telemetry/opentelemetry-go/commit/e016a78c9f5b24a1c2beeaad47686c2f2213f49a
- https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.33.0