PT-2026-94031 · Unknown · Opentelemetry-Go

CVE-2026-81869

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v4.0

5.1

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenTelemetry-Go versions 1.10.0 through 1.32.0
Description The attribute truncation path in sdk/trace/span.go fails to enforce the AttributeValueLengthLimit for string and string-slice attributes that contain the Unicode replacement character U+FFFD. This occurs because the safeTruncateValidUTF8 function treats the replacement rune as invalid UTF-8 and returns the original input, while strings.ToValidUTF8 leaves the rune unchanged, allowing oversized values to persist. An attacker controlling span attribute content can bypass configured limits, leading to increased per-span memory consumption and weakening denial-of-service protections in the instrumented process.
Recommendations Update to version 1.33.0.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103073
AZL-103131
AZL-103143
AZL-103149
AZL-103155
AZL-103161
AZL-103170
AZL-103179
AZL-103191
AZL-103221
AZL-103233
AZL-103239
AZL-103245
AZL-103248
AZL-103257
CVE-2026-81869
GHSA-P9F8-WVJ8-2FG8
GO-2026-6616

Affected Products

Opentelemetry-Go