« Volver al listado

CVE-2026-41178

Estado: AnalizadaMedia (5.3)—

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-41178",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-41178",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-04T15:46:06.715583Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "open-telemetry",
          "product": "go.opentelemetry.io/otel/baggage",
          "versions": [
            {
              "status": "affected",
              "version": "= 1.41.0"
            },
            {
              "status": "affected",
              "version": "= 1.43.0"
            }
          ]
        },
        {
          "vendor": "open-telemetry",
          "product": "go.opentelemetry.io/otel/propagation",
          "versions": [
            {
              "status": "affected",
              "version": "= 1.41.0"
            },
            {
              "status": "affected",
              "version": "= 1.43.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-04T16:16:37.297",
  "references": [
    {
      "url": "https://github.com/open-telemetry/opentelemetry-go/pull/7880",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-789"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue."
    },
    {
      "lang": "es",
      "value": "OpenTelemetry-Go es la implementación en Go de OpenTelemetry. Las versiones 1.41.0 y 1.43.0 eliminaron el rechazo por longitud bruta y esto provoca que 'Parse' procese encabezados de baggage arbitrariamente grandes/inválidos y registre errores, lo que permite DoS mediante entradas sobredimensionadas. Las versiones 1.42.0 y 1.44.0 corrigen el problema."
    }
  ],
  "lastModified": "2026-07-22T20:10:00.127",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:go:*:*",
              "vulnerable": true,
              "matchCriteriaId": "162669E6-6DF4-4673-8120-9A0B3D9614A6",
              "versionEndExcluding": "1.42.0"
            },
            {
              "criteria": "cpe:2.3:a:opentelemetry:opentelemetry:1.43.0:*:*:*:*:go:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1417852C-0B60-4DED-A57B-5D346742643E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}