PT-2026-94018 · Unknown · Opentelemetry-Go

CVE-2026-81870

·

Published

2026-09-16

·

Updated

2026-09-18

CVSS v4.0

2.0

Low

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OpenTelemetry-Go versions 1.5.0 through 1.44.0
Description When sdk/trace.NewTracerProvider constructs a provider, it records a TracerProvider created internal Info-level diagnostic event. In affected versions, the MarshalLog implementations recursively include the provider's span processors, each processor's span exporter, and the client configuration for the OTLP trace exporter. This can lead to the disclosure of OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs in the application logs. Consequently, an unauthorized person or system with access to these logs could determine the internal collector topology or recover credentials and tokens embedded in Zipkin URL user information or query strings. This issue occurs only if an application explicitly enables internal Info logging via otel.SetLogger. The default OpenTelemetry logger does not emit this event, and OTLP authentication headers, TLS key material, and span payloads are not exposed.
Recommendations Update OpenTelemetry-Go to version 1.45.0. As a temporary workaround, keep OpenTelemetry internal logging below the Info verbosity level. Avoid embedding credentials or tokens in exporter endpoint URLs and use authentication headers instead. Restrict access to existing logs and rotate any credentials that may have been recorded.

Exploit

Fix

Insertion into Log File

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103052
AZL-103077
AZL-103082
AZL-103116
AZL-103125
AZL-103128
AZL-103134
AZL-103146
AZL-103152
AZL-103158
AZL-103164
AZL-103167
AZL-103173
AZL-103176
AZL-103200
AZL-103215
AZL-103218
AZL-103236
AZL-103242
AZL-103251
AZL-103260
CLEANSTART-2026-ER31598
CVE-2026-81870
ECHO-D9DD-1C64-6EC8
GHSA-8WMF-6V46-5GFG

Affected Products

Opentelemetry-Go