PT-2026-94032 · Unknown · Opentelemetry-Go

CVE-2026-81871

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OpenTelemetry-Go versions prior to 0.21.0
Description The exporters/otlp/otlplog/otlploggrpc package loads TLS settings from environment variables into cfg.tlsCfg using the loadEnvTLS() function, but the newGRPCDialOptions() function fails to apply this configuration when creating gRPC transport credentials. This causes the connection to fall back to system root CAs and omit the client certificate, bypassing intended mutual TLS (mTLS) and private CA pinning. A network attacker capable of intercepting or spoofing the collector connection using a system-trusted certificate can read or alter log telemetry. This occurs when the application relies solely on environment variables such as OTEL EXPORTER OTLP LOGS CERTIFICATE and OTEL EXPORTER OTLP CERTIFICATE without explicitly providing WithTLSCredentials.
Recommendations Update OpenTelemetry-Go to version 0.21.0. As a temporary workaround, explicitly supply WithTLSCredentials to ensure the intended TLS configuration is applied.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103056
AZL-103110
CLEANSTART-2026-JK20975
CLEANSTART-2026-MT48554
CLEANSTART-2026-VN90217
CVE-2026-81871
GHSA-W34Q-CM8F-9C5X
GO-2026-6508
OPENSUSE-SU-2026:11872-1
OPENSUSE-SU-2026:11875-1
OPENSUSE-SU-2026:11892-1
OPENSUSE-SU-2026:21983-1
OPENSUSE-SU-2026:22010-1
RHSA-2026:68715
RHSA-2026:68716
RHSA-2026:68903
RHSA-2026:68905
RHSA-2026:68910
RHSA-2026:68912
RHSA-2026:68932
RHSA-2026:68941
SUSE-SU-2026:23973-1
SUSE-SU-2026:23984-1
SUSE-SU-2026:23990-1

Affected Products

Opentelemetry-Go