Impact
The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to version 0.151.0, the githubreceiver validated the required_headers configuration at startup, but the request handler did not check those headers on incoming webhook requests. As a result, an unauthenticated sender can bypass an operator's required_headers authentication control and submit arbitrary webhook payloads. When the Secret field is empty, HMAC validation is also skipped, leaving the webhook endpoint without any configured authentication mechanism. Successful exploitation allows an attacker to inject fabricated CI/CD trace data into the observability pipeline, potentially misleading monitoring and creating false operational insights. This flaw exemplifies missing authentication (CWE-306) and improper privilege management (CWE-863), and it impacts data integrity and visibility rather than enabling direct code execution.
Affected Systems
The affected component is the OpenTelemetry Collector Contrib githubreceiver, distributed by the open-telemetry organization. All releases prior to version 0.151.0 are vulnerable. Operators running any older version of opentelemetry-collector-contrib or the githubreceiver must be aware that incoming GitHub webhook requests may be accepted without authentication if the required_headers configuration is present but not enforced or if the Secret field is left empty.
Risk and Exploitability
The weakness has a CVSS score of 6.9, an EPSS score of <1%, and it is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the GitHub webhook endpoint exposed by the collector. An attacker only needs network reach to the endpoint and does not require any privileged access. Because required_headers validation is skipped, no additional authorization is necessary, making exploitation straightforward. The issue is resolved in version 0.151.0.
OpenCVE Enrichment
Github GHSA