Description
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0.
Published: 2026-09-16
Score: 2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability originates from the OpenTelemetry-Go SDK’s default information‑level diagnostic event, which logs a detailed, recursive representation of exporter and client configuration. The logged data includes OTLP gRPC and HTTP collector endpoints, insecure flags, Zipkin collector URLs, and potentially embedded credentials or tokens. Exposing this information in application logs enables attackers or system administrators with log access to map internal collector topology and steal authentication data. The weakness is a data‑leak that can compromise confidentiality but does not directly affect integrity or availability.

Affected Systems

The affected product is OpenTelemetry-Go, version range 1.5.0 to 1.44.0, maintained by the open‑telemetry organization. The vulnerability is present in any application that configures OpenTelemetry with standard logging and then enables internal info logging via otel.SetLogger. Version 1.45.0 and later contain the remediation.

Risk and Exploitability

The CVSS base score of 2 indicates a low technical impact, and the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to either enable internal OpenTelemetry logging or obtain log files from a target system. While the flaw does not allow arbitrary code execution, it can aid reconnaissance and credential theft once access to logs is achieved.

Generated by OpenCVE AI on September 28, 2026 at 14:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenTelemetry-Go to version 1.45.0 or newer.
  • Disable internal OpenTelemetry info‑level diagnostic logging by not calling otel.SetLogger or setting the logger level to WARN or higher.
  • Audit existing log files and redact any sensitive exporter URLs or credentials that may have been captured.

Generated by OpenCVE AI on September 28, 2026 at 14:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8wmf-6v46-5gfg OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
History

Mon, 28 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat cert Manager
Weaknesses CWE-538
CPEs cpe:/a:redhat:cert_manager:1.20::el9
Vendors & Products Redhat
Redhat cert Manager
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Low


Fri, 18 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Opentelemetry
Opentelemetry opentelemetry-go
Vendors & Products Opentelemetry
Opentelemetry opentelemetry-go

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0.
Title OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Weaknesses CWE-200
CWE-532
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Opentelemetry Opentelemetry-go
Redhat Cert Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:58:07.997Z

Reserved: 2026-08-27T17:48:42.120Z

Link: CVE-2026-81870

cve-icon Vulnrichment

Updated: 2026-09-17T14:57:22.276Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T20:17:32.733

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-81870

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-16T20:03:28Z

Links: CVE-2026-81870 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T14:15:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-532

    Insertion of Sensitive Information into Log File

  • CWE-538

    Insertion of Sensitive Information into Externally-Accessible File or Directory