OpenTelemetry Go OTLP HTTP 导出器无限制响应体读取导致 DoS
Security AdvisoryMediumOpenTelemetry
Affected:
- go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp < v0.19.0
- go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp < v1.43.0
- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp < v1.43.0
Fixed in:
- v0.19.0
- v1.43.0
Referenced CVEs: CVE-2026-39882 · 5.3
本文由本平台从 github.com 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。