CVE-2026-81869

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing the valid Unicode replacement character U+FFFD. safeTruncateValidUTF8 treats the valid replacement rune as invalid UTF-8 and returns the original input, while strings.ToValidUTF8 leaves that valid rune unchanged, so a second safeTruncate attempt can also return the oversized value. An attacker who controls span attribute content can retain values longer than the configured limit, increasing per-span memory use and weakening denial-of-service protection in the instrumented process. This issue is fixed in version 1.33.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-176CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-29: 109-29
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve

    🟠 Go SDK OpenTelemetry AttributeValueLengthLimit Bypass (CWE-176: Improper Handling of Unicode Encoding, CWE-400: Uncontrolled Resource Consumption), #CVE-2026-81869 (Moderate) -DC-Sep2026-2626 https://dailycve.com/go-sdk-opentelemetry-attributevaluelengthlimit-bypass-cwe-176-improper-handling-of-unicode-encoding-cwe-400-uncontrolled-resource-consumption-cve-2026-81869-moderate-dc-sep2026-2626/

    0000027
    238 followersView on X

Explore more