Description
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing the valid Unicode replacement character U+FFFD. safeTruncateValidUTF8 treats the valid replacement rune as invalid UTF-8 and returns the original input, while strings.ToValidUTF8 leaves that valid rune unchanged, so a second safeTruncate attempt can also return the oversized value. An attacker who controls span attribute content can retain values longer than the configured limit, increasing per-span memory use and weakening denial-of-service protection in the instrumented process. This issue is fixed in version 1.33.0.
Published: 2026-09-16
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

OpenTelemetry-Go's span attribute truncation mechanism can fail to enforce the configured AttributeValueLengthLimit when span attributes contain the Unicode replacement character U+FFFD. The truncation logic treats that valid rune as invalid UTF‑8, so large attribute values containing U+FFFD bypass length limits and remain in memory, allowing an attacker who controls span attribute content to increase per‑span memory usage and weaken denial‑of‑service protection. This weakness corresponds to CWE-176 and CWE-400.

Affected Systems

All OpenTelemetry-Go deployments from version 1.10.0 up to but not including 1.33.0 are affected. This includes applications that use the open‑telemetry/opentelemetry-go SDK and rely on the default span attribute truncation behavior.

Risk and Exploitability

The CVSS score of 5.1 indicates medium severity. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires an adversary who can inject or influence span attribute values, so the attack vector is likely local or remote through the application. Once triggered, the vulnerability can cause memory exhaustion and provide a denial‑of‑service vector by preventing the trace library from enforcing attribute size limits.

Generated by OpenCVE AI on September 17, 2026 at 21:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update OpenTelemetry-Go to v1.33.0 or later.
  • For environments where an upgrade is postponed, configure AttributeValueLengthLimit to a lower threshold and implement additional validation to replace or remove U+FFFD before sending to trace.
  • Review application data that populates span attributes to eliminate or encode any occurrence of the replacement character.
  • Monitor process memory usage and apply rate limiting or throttling to span generation to protect against potential denial‑of‑service.

Generated by OpenCVE AI on September 17, 2026 at 21:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p9f8-wvj8-2fg8 OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Opentelemetry
Opentelemetry opentelemetry-go
Vendors & Products Opentelemetry
Opentelemetry opentelemetry-go

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing the valid Unicode replacement character U+FFFD. safeTruncateValidUTF8 treats the valid replacement rune as invalid UTF-8 and returns the original input, while strings.ToValidUTF8 leaves that valid rune unchanged, so a second safeTruncate attempt can also return the oversized value. An attacker who controls span attribute content can retain values longer than the configured limit, increasing per-span memory use and weakening denial-of-service protection in the instrumented process. This issue is fixed in version 1.33.0.
Title OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
Weaknesses CWE-176
CWE-400
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Opentelemetry Opentelemetry-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:15:51.501Z

Reserved: 2026-08-27T17:48:42.120Z

Link: CVE-2026-81869

cve-icon Vulnrichment

Updated: 2026-09-17T14:15:17.926Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:22.180

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-81869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-176

    Improper Handling of Unicode Encoding

  • CWE-400

    Uncontrolled Resource Consumption