Description
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS into cfg.tlsCfg, but newGRPCDialOptions does not apply cfg.tlsCfg when creating gRPC transport credentials. The environment-only TLS path instead uses credentials.NewTLS with system roots and no configured client certificate, bypassing intended private CA pinning and mutual TLS unless the application also supplies WithTLSCredentials. A network attacker able to intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. This issue is fixed in version 0.21.0.
Published: 2026-09-16
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Log data confidentiality and integrity breach via mTLS bypass
Action: Patch Now
AI Analysis

Impact

The OpenTelemetry-Go log gRPC exporter unintentionally ignores TLS certificates set via environment variables, causing the exporter to use system root CAs without a client certificate when establishing gRPC connections. This flaw bypasses intended private CA pinning and mutual TLS, lowering the confidentiality and integrity protection of log telemetry. Attackers who can intercept or spoof the collector connection with a system‑trusted certificate could read or alter log data, which aligns with CWE‑295 (Improper Certificate Validation) and CWE‑923 (Inner‑TLS‑Related Misconfiguration).

Affected Systems

All releases of OpenTelemetry-Go prior to 0.21.0 that use the exporters/otlp/otlplog/otlploggrpc package are affected. The issue applies to the OpenTelemetry-Go project maintained by the OpenTelemetry community, specifically any Go applications that import and use the OTLP gRPC log exporter without providing explicit TLS credentials.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.3, indicating moderate severity, while the EPSS score of less than 1% shows a low likelihood of exploitation in the current environment. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need network access to the telemetry channel and the ability to present a system‑trusted certificate to impersonate the collector. The primary risk is compromise of log confidentiality and integrity rather than availability.

Generated by OpenCVE AI on September 18, 2026 at 01:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenTelemetry-Go to version 0.21.0 or later to apply the TLS credential handling fix.
  • If an upgrade is not yet possible, configure the application to explicitly supply TLS credentials to the exporter using the WithTLSCredentials option or equivalent configuration, ensuring the exporter does not rely on environment variables alone.
  • Restrict network access to the telemetry collector to trusted networks or protect the channel with firewall rules or VPN so that only authorized traffic can reach it, reducing the chance of interception or spoofing.

Generated by OpenCVE AI on September 18, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w34q-cm8f-9c5x OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
History

Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Fri, 18 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Opentelemetry
Opentelemetry opentelemetry-go
Vendors & Products Opentelemetry
Opentelemetry opentelemetry-go

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS into cfg.tlsCfg, but newGRPCDialOptions does not apply cfg.tlsCfg when creating gRPC transport credentials. The environment-only TLS path instead uses credentials.NewTLS with system roots and no configured client certificate, bypassing intended private CA pinning and mutual TLS unless the application also supplies WithTLSCredentials. A network attacker able to intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. This issue is fixed in version 0.21.0.
Title OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Weaknesses CWE-295
CWE-923
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Opentelemetry Opentelemetry-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:24:00.081Z

Reserved: 2026-08-27T17:48:42.120Z

Link: CVE-2026-81871

cve-icon Vulnrichment

Updated: 2026-09-17T17:10:35.397Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:22.323

Modified: 2026-09-30T17:31:44.573

Link: CVE-2026-81871

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T20:43:40Z

Links: CVE-2026-81871 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:00:16Z

Weaknesses
  • CWE-295

    Improper Certificate Validation

  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints