{"id":"UBUNTU-CVE-2026-81869","details":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing the valid Unicode replacement character U+FFFD. safeTruncateValidUTF8 treats the valid replacement rune as invalid UTF-8 and returns the original input, while strings.ToValidUTF8 leaves that valid rune unchanged, so a second safeTruncate attempt can also return the oversized value. An attacker who controls span attribute content can retain values longer than the configured limit, increasing per-span memory use and weakening denial-of-service protection in the instrumented process. This issue is fixed in version 1.33.0.","modified":"2026-09-18T12:30:21.212128215Z","published":"2026-09-18T00:00:00Z","upstream":["CVE-2026-81869"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-81869"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-81869"},{"type":"REPORT","url":"https://github.com/open-telemetry/opentelemetry-go/commit/e016a78c9f5b24a1c2beeaad47686c2f2213f49a"},{"type":"REPORT","url":"https://github.com/open-telemetry/opentelemetry-go/issues/5996"},{"type":"REPORT","url":"https://github.com/open-telemetry/opentelemetry-go/pull/5997"},{"type":"REPORT","url":"https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.33.0"},{"type":"REPORT","url":"https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-p9f8-wvj8-2fg8"}],"affected":[{"package":{"name":"golang-opentelemetry-otel","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-opentelemetry-otel?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.0-2"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-opentelemetry-otel-dev","binary_version":"1.1.0-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-81869.json"}},{"package":{"name":"golang-opentelemetry-otel","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/golang-opentelemetry-otel?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.16.0-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.16.0-1","binary_name":"golang-opentelemetry-otel-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-81869.json"}},{"package":{"name":"golang-opentelemetry-otel","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/golang-opentelemetry-otel?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.31.0-4","1.31.0-5","1.31.0-6"],"ecosystem_specific":{"binaries":[{"binary_version":"1.31.0-6","binary_name":"golang-opentelemetry-otel-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-81869.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]}