PT-2026-94018 · Unknown · Opentelemetry-Go
CVE-2026-81870
·
Published
2026-09-16
·
Updated
2026-09-18
CVSS v4.0
2.0
Low
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OpenTelemetry-Go versions 1.5.0 through 1.44.0
Description
When
sdk/trace.NewTracerProvider constructs a provider, it records a TracerProvider created internal Info-level diagnostic event. In affected versions, the MarshalLog implementations recursively include the provider's span processors, each processor's span exporter, and the client configuration for the OTLP trace exporter. This can lead to the disclosure of OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs in the application logs. Consequently, an unauthorized person or system with access to these logs could determine the internal collector topology or recover credentials and tokens embedded in Zipkin URL user information or query strings. This issue occurs only if an application explicitly enables internal Info logging via otel.SetLogger. The default OpenTelemetry logger does not emit this event, and OTLP authentication headers, TLS key material, and span payloads are not exposed.Recommendations
Update OpenTelemetry-Go to version 1.45.0.
As a temporary workaround, keep OpenTelemetry internal logging below the Info verbosity level.
Avoid embedding credentials or tokens in exporter endpoint URLs and use authentication headers instead.
Restrict access to existing logs and rotate any credentials that may have been recorded.
Exploit
Fix
Insertion into Log File
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opentelemetry-Go