PT-2026-31016 · Opentelemetry · Opentelemetry-Go

·

CVE-2026-29181

·

Published

2026-04-07

·

Updated

2026-07-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenTelemetry-Go versions 1.36.0 through 1.40.0
Description The OpenTelemetry-Go implementation is susceptible to a remote request amplification issue due to the way it handles multi-value baggage headers. Specifically, the extractMultiBaggage function in propagation/baggage.go parses each baggage header field-value independently and aggregates the results. An attacker can exploit this by sending numerous baggage header lines, even if each individual value is within the 8192-byte limit, leading to increased CPU usage and memory allocations. This can result in higher latency and potential denial-of-service conditions. The vulnerability is related to the parsing of headers received in HTTP requests. The vulnerable function is extractMultiBaggage.
Recommendations Update to version 1.41.0 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AG91746
CLEANSTART-2026-AK43046
CLEANSTART-2026-AP10784
CLEANSTART-2026-AP81049
CLEANSTART-2026-AR14847
CLEANSTART-2026-AS38473
CLEANSTART-2026-BG93699
CLEANSTART-2026-BM78291
CLEANSTART-2026-BP02821
CLEANSTART-2026-BR79647
CLEANSTART-2026-CL67452
CLEANSTART-2026-DH72490
CLEANSTART-2026-EH36582
CLEANSTART-2026-EI06494
CLEANSTART-2026-EP65920
CLEANSTART-2026-EY79095
CLEANSTART-2026-GB36430
CLEANSTART-2026-GB38700
CLEANSTART-2026-GJ69402
CLEANSTART-2026-GM82388
CLEANSTART-2026-GQ00159
CLEANSTART-2026-GZ11549
CLEANSTART-2026-GZ35045
CLEANSTART-2026-HO16255
CLEANSTART-2026-IC09970
CLEANSTART-2026-IN26303
CLEANSTART-2026-JQ70227
CLEANSTART-2026-JY65496
CLEANSTART-2026-KJ72865
CLEANSTART-2026-KL41807
CLEANSTART-2026-LA07853
CLEANSTART-2026-LG79681
CLEANSTART-2026-LY44407
CLEANSTART-2026-MA83809
CLEANSTART-2026-MJ60235
CLEANSTART-2026-MV81821
CLEANSTART-2026-MZ00063
CLEANSTART-2026-NM43450
CLEANSTART-2026-NT80635
CLEANSTART-2026-OD56729
CLEANSTART-2026-OH26633
CLEANSTART-2026-ON19155
CLEANSTART-2026-OX51942
CLEANSTART-2026-OY74734
CLEANSTART-2026-QO29688
CLEANSTART-2026-QR52625
CLEANSTART-2026-QT53274
CLEANSTART-2026-QX43073
CLEANSTART-2026-RT07393
CLEANSTART-2026-RW78583
CLEANSTART-2026-RZ44006
CLEANSTART-2026-SO47947
CLEANSTART-2026-SQ76279
CLEANSTART-2026-SY48547
CLEANSTART-2026-TH33219
CLEANSTART-2026-UC73978
CLEANSTART-2026-UY49411
CLEANSTART-2026-VE68915
CLEANSTART-2026-WF25734
CLEANSTART-2026-WV75091
CLEANSTART-2026-XJ06210
CLEANSTART-2026-XQ84127
CLEANSTART-2026-XR35583
CLEANSTART-2026-YB92538
CLEANSTART-2026-YF30779
CLEANSTART-2026-YH23797
CLEANSTART-2026-YP16651
CLEANSTART-2026-YY48565
CLEANSTART-2026-YZ69292
CVE-2026-29181
GHSA-MH2Q-Q3FH-2475
GO-2026-5506
OPENSUSE-SU-2026:11173-1
SUSE-SU-2026:2493-1

Affected Products

Opentelemetry-Go