Description
The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiver/githubreceiver/trace_receiver.go handleReq() does not check those headers on incoming webhook requests. An unauthenticated sender can therefore bypass an operator's required_headers authentication control and submit arbitrary webhook payloads. When the Secret field is empty, github.ValidatePayload also skips HMAC validation, leaving the webhook endpoint without either configured authentication mechanism. Successful exploitation can inject fabricated CI/CD trace data into the observability pipeline. This issue is fixed in version 0.151.0.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass allowing injection of arbitrary CI/CD trace data
Action: Apply Patch
AI Analysis

Impact

The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to version 0.151.0, the githubreceiver validated the required_headers configuration at startup, but the request handler did not check those headers on incoming webhook requests. As a result, an unauthenticated sender can bypass an operator's required_headers authentication control and submit arbitrary webhook payloads. When the Secret field is empty, HMAC validation is also skipped, leaving the webhook endpoint without any configured authentication mechanism. Successful exploitation allows an attacker to inject fabricated CI/CD trace data into the observability pipeline, potentially misleading monitoring and creating false operational insights. This flaw exemplifies missing authentication (CWE-306) and improper privilege management (CWE-863), and it impacts data integrity and visibility rather than enabling direct code execution.

Affected Systems

The affected component is the OpenTelemetry Collector Contrib githubreceiver, distributed by the open-telemetry organization. All releases prior to version 0.151.0 are vulnerable. Operators running any older version of opentelemetry-collector-contrib or the githubreceiver must be aware that incoming GitHub webhook requests may be accepted without authentication if the required_headers configuration is present but not enforced or if the Secret field is left empty.

Risk and Exploitability

The weakness has a CVSS score of 6.9, an EPSS score of <1%, and it is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the GitHub webhook endpoint exposed by the collector. An attacker only needs network reach to the endpoint and does not require any privileged access. Because required_headers validation is skipped, no additional authorization is necessary, making exploitation straightforward. The issue is resolved in version 0.151.0.

Generated by OpenCVE AI on September 20, 2026 at 16:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the OpenTelemetry Collector Contrib githubreceiver component to version 0.151.0 or later.
  • Configure a non-empty Secret field for HMAC validation; if configured, the collector will reject unsigned payloads.
  • Restrict access to the webhook endpoint to trusted IP addresses or protect it behind a reverse proxy that enforces authentication before the request reaches the collector.

Generated by OpenCVE AI on September 20, 2026 at 16:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w5cv-pw74-4rxc opentelemetry-collector-contrib: githubreceiver silently ignores configured required_headers authentication
History

Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Opentelemetry
Opentelemetry opentelemetry Collector Contrib
Vendors & Products Opentelemetry
Opentelemetry opentelemetry Collector Contrib

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiver/githubreceiver/trace_receiver.go handleReq() does not check those headers on incoming webhook requests. An unauthenticated sender can therefore bypass an operator's required_headers authentication control and submit arbitrary webhook payloads. When the Secret field is empty, github.ValidatePayload also skips HMAC validation, leaving the webhook endpoint without either configured authentication mechanism. Successful exploitation can inject fabricated CI/CD trace data into the observability pipeline. This issue is fixed in version 0.151.0.
Title OpenTelemetry githubreceiver silently ignores configured required_headers authentication
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Opentelemetry Opentelemetry Collector Contrib
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:45:43.493Z

Reserved: 2026-06-17T00:13:10.651Z

Link: CVE-2026-55701

cve-icon Vulnrichment

Updated: 2026-09-17T14:45:39.787Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:15.617

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-55701

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:05:15Z

Links: CVE-2026-55701 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-863

    Incorrect Authorization