Impact
fluent‑plugin‑opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to version 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompresses payloads into memory without enforcing maximum size thresholds. When the OpenTelemetry ingestion endpoint is exposed to an untrusted network, an attacker can send an excessively large request or a highly compressed payload that expands in memory, exhausting system memory and causing the Fluentd process to terminate. This disruption halts all log collection and forwarding on the affected node. The issue is fixed by upgrading to version 0.5.3.
Affected Systems
The vulnerability affects the fluent‑plugins‑nursery implementation of fluent‑plugin‑opentelemetry prior to version 0.5.3. Systems running any earlier release expose an OpenTelemetry ingestion endpoint to an untrusted network and are susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. An EPSS score of < 1% shows a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access to the OpenTelemetry ingestion endpoint, and successful exploitation results in a denial of service that disrupts logging infrastructure, potentially impacting monitoring and alerting capabilities.
OpenCVE Enrichment
Github GHSA