{"id":"UBUNTU-CVE-2023-25151","details":"opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` uses the `httpconv.ServerRequest` function to annotate metric measurements for the `http.server.request_content_length`, `http.server.response_content_length`, and `http.server.duration` instruments. The `ServerRequest` function sets the `http.target` attribute value to be the whole request URI (including the query string)[^1]. The metric instruments do not \"forget\" previous measurement attributes when `cumulative` temporality is used, this means the cardinality of the measurements allocated is directly correlated with the unique URIs handled. If the query string is constantly random, this will result in a constant increase in memory allocation that can be used in a denial-of-service attack. This issue has been addressed in version 0.39.0. Users are advised to upgrade. There are no known workarounds for this issue.","modified":"2026-05-20T16:13:19.182388989Z","published":"2023-02-08T20:15:00Z","upstream":["CVE-2023-25151"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-25151"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-25151"}],"affected":[{"package":{"name":"golang-opentelemetry-contrib","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/golang-opentelemetry-contrib?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.56.0-5"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-opentelemetry-contrib-dev","binary_version":"0.56.0-5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-25151.json"}},{"package":{"name":"golang-opentelemetry-contrib","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/golang-opentelemetry-contrib?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.56.0-5"],"ecosystem_specific":{"binaries":[{"binary_version":"0.56.0-5","binary_name":"golang-opentelemetry-contrib-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-25151.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}