Skip to content

OpenTelemetry-Go Contrib vulnerable to denial of service in otelhttp due to unbound cardinality metrics #5089

@zroubalik

Description

@zroubalik

Report

GHSA-rcjv-mgp8-qvmr

OpenTelemetry-Go Contrib has a handler wrapper otelhttp that adds the following labels by deafult that have unbound cardinality:

http.user_agent
http.method

This leads to the server's potential memory exhaustion when many malicious requests are sent to it.

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

Status

Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions