PT-2026-94032 · Unknown · Opentelemetry-Go
CVE-2026-81871
·
Published
2026-09-16
·
Updated
2026-10-01
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OpenTelemetry-Go versions prior to 0.21.0
Description
The
exporters/otlp/otlplog/otlploggrpc package loads TLS settings from environment variables into cfg.tlsCfg using the loadEnvTLS() function, but the newGRPCDialOptions() function fails to apply this configuration when creating gRPC transport credentials. This causes the connection to fall back to system root CAs and omit the client certificate, bypassing intended mutual TLS (mTLS) and private CA pinning. A network attacker capable of intercepting or spoofing the collector connection using a system-trusted certificate can read or alter log telemetry. This occurs when the application relies solely on environment variables such as OTEL EXPORTER OTLP LOGS CERTIFICATE and OTEL EXPORTER OTLP CERTIFICATE without explicitly providing WithTLSCredentials.Recommendations
Update OpenTelemetry-Go to version 0.21.0.
As a temporary workaround, explicitly supply
WithTLSCredentials to ensure the intended TLS configuration is applied.Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opentelemetry-Go