multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
Upstream fixed versions: go.opentelemetry.io/otel/baggage: v1.41.0; go.opentelemetry.io/otel/propagation: v1.41.0
details
- Finding IDs
- F-OTELGO-001
- CVE
- CVE-2026-29181
- GHSA
- GHSA-mh2q-q3fh-2475
- Status
- patched
- Fixed in
- go.opentelemetry.io/otel/baggage: v1.41.0; go.opentelemetry.io/otel/propagation: v1.41.0
- Note
- GHSA-mh2q-q3fh-2475
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
- Upstream CWE
- CWE-400
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream fixed versions
- go.opentelemetry.io/otel/baggage: v1.41.0; go.opentelemetry.io/otel/propagation: v1.41.0
- Upstream affected ranges
- go.opentelemetry.io/otel/baggage: >= v1.36.0, <= 1.40.0; go.opentelemetry.io/otel/propagation: >= v1.36.0, <= 1.40.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-OTELGO-001: Resource limits. Baggage handling permits disproportionate resource consumption. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-OTELGO-001
Security area (1seal assessment): Availability. Repeated baggage header values amplify parsing work and allocations beyond the per-value limit. Reviewed 21 Sep 2026.