Impact
The vulnerability originates from the OpenTelemetry-Go SDK’s default information‑level diagnostic event, which logs a detailed, recursive representation of exporter and client configuration. The logged data includes OTLP gRPC and HTTP collector endpoints, insecure flags, Zipkin collector URLs, and potentially embedded credentials or tokens. Exposing this information in application logs enables attackers or system administrators with log access to map internal collector topology and steal authentication data. The weakness is a data‑leak that can compromise confidentiality but does not directly affect integrity or availability.
Affected Systems
The affected product is OpenTelemetry-Go, version range 1.5.0 to 1.44.0, maintained by the open‑telemetry organization. The vulnerability is present in any application that configures OpenTelemetry with standard logging and then enables internal info logging via otel.SetLogger. Version 1.45.0 and later contain the remediation.
Risk and Exploitability
The CVSS base score of 2 indicates a low technical impact, and the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to either enable internal OpenTelemetry logging or obtain log files from a target system. While the flaw does not allow arbitrary code execution, it can aid reconnaissance and credential theft once access to logs is achieved.
OpenCVE Enrichment
Github GHSA