Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w8rr-5gcm-pp58 | opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies |
Fri, 10 Apr 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opentelemetry opentelemetry
|
|
| CPEs | cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:go:*:* | |
| Vendors & Products |
Opentelemetry opentelemetry
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opentelemetry
Opentelemetry opentelemetry-go |
|
| Vendors & Products |
Opentelemetry
Opentelemetry opentelemetry-go |
Wed, 08 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can mitm the exporter connection). This vulnerability is fixed in 1.43.0. | |
| Title | OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies | |
| Weaknesses | CWE-789 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-09T20:22:03.109Z
Reserved: 2026-04-07T20:32:03.010Z
Link: CVE-2026-39882
Updated: 2026-04-09T20:21:56.599Z
Status : Analyzed
Published: 2026-04-08T21:17:00.547
Modified: 2026-04-09T18:39:55.730
Link: CVE-2026-39882
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:40:34Z
Github GHSA