Description
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchronous export buffer while the exporter is backpressured. NewBatchingProcessor wraps the exporter with newBufferExporter(exporter, 1), and the poll loop calls queue.TryDequeue and bufferExporter.EnqueueExport before immediately signaling pollTrigger whenever the queue remains at or above batchSize. Because a failed nonblocking EnqueueExport leaves the queue length unchanged, the processor repeatedly retries without waiting for its ticker, exhausting CPU and degrading or denying service in the embedding process. This issue is fixed in version 0.21.0.
Published: 2026-09-16
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (CPU exhaustion)
Action: Immediate Patch
AI Analysis

Impact

The BatchingProcessor in OpenTelemetry-Go can enter a tight CPU loop when log emission driven by an attacker fills its asynchronous export buffer while the exporter experiences backpressure. This causes the processor to retry exporting without waiting for its ticker, continuously consuming CPU and degrading or denying service in the host process. The weakness aligns with CWE-400 (Uncontrolled Resource Consumption), CWE-834 (Use of Timeouts), and CWE-835 (Busy Wait).

Affected Systems

The vulnerability affects the OpenTelemetry Go library (go.opentelemetry.io/otel/sdk/log). All releases prior to version 0.21.0 are affected; version 0.21.0 and later contain the fix.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to generate log traffic that fills the export buffer; this could be achieved by running malicious code within the application or through a component with privileged logging access. Patching mitigates the risk by replacing the faulty buffer handling logic with a safe implementation.

Generated by OpenCVE AI on September 20, 2026 at 04:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the OpenTelemetry-Go library to version 0.21.0 or later to apply the official fix.
  • If an immediate upgrade is not possible, limit the rate at which logs are emitted or isolate the logger to prevent the export buffer from reaching capacity.
  • Implement application‑level CPU monitoring for the BatchingProcessor and configure alerts or automatic restarts when usage exceeds an acceptable threshold.

Generated by OpenCVE AI on September 20, 2026 at 04:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hjf4-fphr-2h65 OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
History

Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-835
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


Thu, 17 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Opentelemetry
Opentelemetry opentelemetry-go
Vendors & Products Opentelemetry
Opentelemetry opentelemetry-go

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchronous export buffer while the exporter is backpressured. NewBatchingProcessor wraps the exporter with newBufferExporter(exporter, 1), and the poll loop calls queue.TryDequeue and bufferExporter.EnqueueExport before immediately signaling pollTrigger whenever the queue remains at or above batchSize. Because a failed nonblocking EnqueueExport leaves the queue length unchanged, the processor repeatedly retries without waiting for its ticker, exhausting CPU and degrading or denying service in the embedding process. This issue is fixed in version 0.21.0.
Title OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Weaknesses CWE-400
CWE-834
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Opentelemetry Opentelemetry-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T13:36:27.289Z

Reserved: 2026-08-27T17:48:42.121Z

Link: CVE-2026-81872

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:15.500Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:22.467

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-81872

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T20:42:23Z

Links: CVE-2026-81872 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-834

    Excessive Iteration

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')