Threat Advisory

OpenTelemetry-Go Flaw Causes Denial of Service Through CPU Exhaustion

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability exists in OpenTelemetry-Go, allowing an attacker to cause denial of service through CPU exhaustion when sustained log emission occurs and the exporter or downstream collector is slow, blocked, or backpressured. The flaw affects versions prior to 0.21.0 of go.opentelemetry., specifically the BatchProcessor component which can enter a tight CPU loop when the asynchronous export buffer is full. This occurs due to repeated immediate export retries under exporter backpressure, causing repeated dequeuing and enqueuing operations without waiting for the ticker. The vulnerability has a CVSS v4 score of 6.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N) and is classified as CWE-400, CWE-834. The impact is limited to the embedding process but can degrade or deny service for that application.

RECOMMENDATION:

We recommend you to update OpenTelemetry-Go to version 0.21.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability exists in OpenTelemetry-Go, allowing an attacker to cause denial of service through CPU exhaustion when sustained log emission occurs and the exporter or downstream collector is slow, blocked, or backpressured. The flaw affects versions prior to 0.21.0 of go.opentelemetry., specifically the BatchProcessor component which can enter a tight CPU loop when the asynchronous export buffer is full. This occurs due to repeated immediate export retries under exporter backpressure, causing repeated dequeuing and enqueuing operations without waiting for the ticker. The vulnerability has a CVSS v4 score of 6.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N) and is classified as CWE-400, CWE-834. The impact is limited to the embedding process but can degrade or deny service for that application.

RECOMMENDATION:

We recommend you to update OpenTelemetry-Go to version 0.21.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu