{"id":"CVE-2026-39882","title":"github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Memory exhaustion via uncapped HTTP response body reading (CVE-2026-39882)","summary":"A flaw was found in OpenTelemetry-Go. The otlp HTTP exporters read the full HTTP response body into an in-memory buffer without a size cap. A remote attacker, by controlling the collector endpoint or performing a man-in-the-middle (MITM) a…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-770","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.22","affected":["multicluster_engine_for_kubernetes","openshift_container_platform 4.22"],"patched":["openshift_container_platform 4.22"],"published":"2026-04-08","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:49:20+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39882.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39882.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-39882"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2456727"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-39882"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39882"},{"url":"https://github.com/open-telemetry/opentelemetry-go/pull/8108"},{"url":"https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w8rr-5gcm-pp58"},{"url":"https://access.redhat.com/errata/RHSA-2026:54770"},{"url":"https://access.redhat.com/errata/RHSA-2026:37585"},{"url":"https://github.com/open-telemetry/opentelemetry-go"},{"url":"http://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.43.0"}],"tags":["csaf","vex","red-hat","osv","go","score-dispute"],"epss":0.0019,"epssPercentile":0.08935,"aliases":["GHSA-w8rr-5gcm-pp58","GO-2026-4985"],"ecosystem":"go","scores":{"vendor":7.5,"osv":5.3},"ingestedAt":"2026-07-09T18:56:36.964Z","slug":"CVE-2026-39882","body":"## Overview\n\nA flaw was found in OpenTelemetry-Go. The otlp HTTP exporters read the full HTTP response body into an in-memory buffer without a size cap. A remote attacker, by controlling the collector endpoint or performing a man-in-the-middle (MITM) attack on the exporter connection, can exploit this to cause memory exhaustion. This vulnerability can lead to a Denial of Service (DoS) for the affected system.\n\n## Vendor advisories\n\n- **RHSA-2026:54770** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:54770)\n- **RHSA-2026:37585** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-07-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:37585)\n- **Red Hat VEX** · Important · affected: Multicluster Engine for Kubernetes · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39882.json)\n\n**github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Memory exhaustion via uncapped HTTP response body reading** — rated Important by Red Hat. Released 2026-04-08, updated 2026-09-21.\n\nAffected:\n\n- Multicluster Engine for Kubernetes\n\nFixed:\n\n- Red Hat OpenShift Container Platform 4.22\n\nNot affected:\n\n- Red Hat OpenShift Container Platform 4.22\n\n## Remediation\n\nFor OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:\n\nhttps://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/\n\nYou may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.\n\nThe sha values for the release are as fol… https://access.redhat.com/errata/RHSA-2026:54770\nFor OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:\n\nhttps://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/\n\nYou may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.\n\nThe sha values for the release are as fol… https://access.redhat.com/errata/RHSA-2026:37585\n\n## Package advisory (CVE-2026-39882)\n\nAffected packages:\n\n- `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp < 1.43.0`\n- `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp < 1.43.0`\n- `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp < 0.19.0`\n\nPatched in:\n\n- `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp 1.43.0`\n- `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp 1.43.0`\n- `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp 0.19.0`\n\nSource: https://osv.dev/vulnerability/GHSA-w8rr-5gcm-pp58","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208479,"id":"CVE-2026-39882","ts":1790005714614,"field":"cvss","old":"5.3","new":"7.5"},{"seq":208478,"id":"CVE-2026-39882","ts":1790005714614,"field":"severity","old":"medium","new":"high"}]}