Impact
The BatchingProcessor in OpenTelemetry-Go can enter a tight CPU loop when log emission driven by an attacker fills its asynchronous export buffer while the exporter experiences backpressure. This causes the processor to retry exporting without waiting for its ticker, continuously consuming CPU and degrading or denying service in the host process. The weakness aligns with CWE-400 (Uncontrolled Resource Consumption), CWE-834 (Use of Timeouts), and CWE-835 (Busy Wait).
Affected Systems
The vulnerability affects the OpenTelemetry Go library (go.opentelemetry.io/otel/sdk/log). All releases prior to version 0.21.0 are affected; version 0.21.0 and later contain the fix.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to generate log traffic that fills the export buffer; this could be achieved by running malicious code within the application or through a component with privileged logging access. Patching mitigates the risk by replacing the faulty buffer handling logic with a safe implementation.
OpenCVE Enrichment
Github GHSA