The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
MediumVulnerability
GHSA-hjf4-fphr-2h65: OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
- Identifiers
- CVE-2026-81872GHSA-hjf4-fphr-2h65
- Published
- Record updated
- Affected
- go.opentelemetry.io/otel/sdk/log < 0.21.0
- Fixed in
- 0.21.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.4%
Summary
GHSA-hjf4-fphr-2h65 affects the BatchingProcessor in go.opentelemetry.io/otel/sdk/log, introduced in commit 4af9c20. When the asynchronous export buffer is full under exporter backpressure, the poll loop retriggers itself without waiting for the ticker, causing a CPU busy-spin. An attacker who can drive sustained high-volume log emission can exhaust CPU and deny service to the embedding process.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.