The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
GHSA-p9f8-wvj8-2fg8: OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
- Identifiers
- CVE-2026-81869GHSA-p9f8-wvj8-2fg8
- Published
- Record updated
Summary
The OpenTelemetry Go SDK trace package fails to enforce AttributeValueLengthLimit for string attributes containing the valid Unicode replacement character U+FFFD. Because safeTruncateValidUTF8 treats any utf8.RuneError as invalid UTF-8, an oversized attacker-controlled value containing U+FFFD is returned untruncated, which increases per-span memory use. The issue requires a deployment with attribute value length limits enabled and attacker-controlled data recorded into span attributes, and the finding is rated low severity with no confidentiality or integrity impact.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.