The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-2014 | The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1. |
![]() |
GHSA-c74f-6mfw-mm4v | Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T03:30:13.165Z
Reserved: 2024-05-20T21:07:48.190Z
Link: CVE-2024-36129

Updated: 2024-07-19T12:59:27.966Z

Status : Modified
Published: 2024-06-05T18:15:10.833
Modified: 2024-11-21T09:21:40.733
Link: CVE-2024-36129


No data.