Skip to content

The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.

MediumVulnerability

GHSA-hjf4-fphr-2h65: OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full

Published
Record updated
Affected
  • go.opentelemetry.io/otel/sdk/log < 0.21.0
Fixed in
0.21.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

GHSA-hjf4-fphr-2h65 affects the BatchingProcessor in go.opentelemetry.io/otel/sdk/log, introduced in commit 4af9c20. When the asynchronous export buffer is full under exporter backpressure, the poll loop retriggers itself without waiting for the ticker, causing a CPU busy-spin. An attacker who can drive sustained high-volume log emission can exhaust CPU and deny service to the embedding process.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.