Impact
OpenTelemetry-Go's span attribute truncation mechanism can fail to enforce the configured AttributeValueLengthLimit when span attributes contain the Unicode replacement character U+FFFD. The truncation logic treats that valid rune as invalid UTF‑8, so large attribute values containing U+FFFD bypass length limits and remain in memory, allowing an attacker who controls span attribute content to increase per‑span memory usage and weaken denial‑of‑service protection. This weakness corresponds to CWE-176 and CWE-400.
Affected Systems
All OpenTelemetry-Go deployments from version 1.10.0 up to but not including 1.33.0 are affected. This includes applications that use the open‑telemetry/opentelemetry-go SDK and rely on the default span attribute truncation behavior.
Risk and Exploitability
The CVSS score of 5.1 indicates medium severity. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires an adversary who can inject or influence span attribute values, so the attack vector is likely local or remote through the application. Once triggered, the vulnerability can cause memory exhaustion and provide a denial‑of‑service vector by preventing the trace library from enforcing attribute size limits.
OpenCVE Enrichment
Github GHSA