CVE-2024-36129
Estado: ModificadaAlta (7.5)—
The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.24%
- Percentil entre todas las CVEs puntuadas: 68
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-119
- CWE-119
Referencias
- https://github.com/open-telemetry/opentelemetry-collector/pull/10289
- https://github.com/open-telemetry/opentelemetry-collector/pull/10323
- https://github.com/open-telemetry/opentelemetry-collector/security/advisories/GHSA-c74f-6mfw-mm4v
- https://opentelemetry.io/blog/2024/cve-2024-36129
- https://github.com/open-telemetry/opentelemetry-collector/pull/10289
- https://github.com/open-telemetry/opentelemetry-collector/pull/10323
- https://github.com/open-telemetry/opentelemetry-collector/security/advisories/GHSA-c74f-6mfw-mm4v
- https://opentelemetry.io/blog/2024/cve-2024-36129
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-36129",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-36129",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-07-19T12:31:23.085235Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 4.2,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "open-telemetry",
"product": "opentelemetry-collector",
"versions": [
{
"status": "affected",
"version": "< 0.102.1"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:*:*:*"
],
"vendor": "opentelemetry",
"product": "opentelemetry",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "0.102.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-06-05T18:15:10.833",
"references": [
{
"url": "https://github.com/open-telemetry/opentelemetry-collector/pull/10289",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/open-telemetry/opentelemetry-collector/pull/10323",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/open-telemetry/opentelemetry-collector/security/advisories/GHSA-c74f-6mfw-mm4v",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://opentelemetry.io/blog/2024/cve-2024-36129",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/open-telemetry/opentelemetry-collector/pull/10289",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/open-telemetry/opentelemetry-collector/pull/10323",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/open-telemetry/opentelemetry-collector/security/advisories/GHSA-c74f-6mfw-mm4v",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://opentelemetry.io/blog/2024/cve-2024-36129",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.\n"
},
{
"lang": "es",
"value": "OpenTelemetry Collector ofrece una implementación independiente del proveedor sobre cómo recibir, procesar y exportar datos de telemetría. Una vulnerabilidad de descompresión insegura permite a atacantes no autenticados bloquear el recopilador mediante un consumo excesivo de memoria. La versión 0.102.1 de OTel Collector soluciona este problema. También está corregido en la versión 0.102.0 del módulo confighttp y en la versión 0.102.1 del módulo configgrpc."
}
],
"lastModified": "2026-06-17T07:36:09.610",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:opentelemetry:configgrpc:*:*:*:*:*:go:*:*",
"vulnerable": true,
"matchCriteriaId": "327CE873-41EC-401C-AF22-0A179C4A37D0",
"versionEndExcluding": "0.102.1"
},
{
"criteria": "cpe:2.3:a:opentelemetry:confighttp:*:*:*:*:*:go:*:*",
"vulnerable": true,
"matchCriteriaId": "13F55EF7-B8F7-4344-BE0C-C8129E57A306",
"versionEndExcluding": "0.102.0"
},
{
"criteria": "cpe:2.3:a:opentelemetry:opentelemetry_collector:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F3C518A-75AF-4A34-83DF-9FCB346FE5EF",
"versionEndExcluding": "0.102.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}