GHSA-p9f8-wvj8-2fg8: Go/go.opentelemetry.io/otel/sdk vulnerability

Published Sep 29, 2026
·
Updated

Summary

The OpenTelemetry Go SDK trace package can fail to enforce AttributeValueLengthLimit for string attributes containing the valid Unicode replacement character U+FFFD. An oversized attacker-controlled attribute value that includes U+FFFD is returned untruncated, bypassing the configured memory/DoS protection and allowing increased per-span memory usage. The finding is low severity because it requires a deployment with attribute value length limits enabled and attacker-controlled data being recorded into span attributes.

Introduced in commit 49a6536

Details

String and string-slice span attributes are truncated through safeTruncate when AttributeValueLengthLimit is non-negative. The finding evidence identifies this enforcement path in sdk/trace/span.go:303-331, with string attributes passed to safeTruncate at sdk/trace/span.go:309-310 and string-slice entries passed to safeTruncate in the loop beginning at sdk/trace/span.go:312.

safeTruncate first calls safeTruncateValidUTF8; if that returns ok=false, it calls strings.ToValidUTF8(input, "") and retries. The relevant code is identified in sdk/trace/span.go:337-355. safeTruncateValidUTF8 treats any utf8.RuneError from utf8.DecodeRuneInString as invalid UTF-8 and immediately returns the original input with ok=false. However, Go also returns utf8.RuneError for a valid encoded U+FFFD rune. The validation artifact confirms this behavior with output r=U+FFFD size=3 runeError=true.

For an input such as "AAAA" + U+FFFD + strings.Repeat("B", 20) and a limit of 5, the first truncation attempt sees U+FFFD as utf8.RuneError and returns the full input with ok=false. strings.ToValidUTF8 does not remove the valid U+FFFD rune, so the second attempt returns the same full input. As a result, the span attribute value remains 27 bytes long even though the configured limit is 5.

PoC

validation-artifact.zip

The validation artifact contains a package-level Go test at validation-artifact.tar:safetruncatebypass/safetruncatepoctest.go and supporting output at validation-artifact.tar:safetruncatebypass/runecheckoutput.txt.

Reproduction configuration: - Repository: pellared/opentelemetry-go - Commit: 49a6536 from September 12, 2022 - Package/module path: sdk/trace under the sdk module - Attribute value length limit used by the PoC: limit := 5 - Dependencies must be available through the network or a local module cache/vendor directory.

Commands: sh cd /path/to/opentelemetry-go git checkout 49a6536 tar -xOf /path/to/validation-artifact.tar safetruncatebypass/safetruncatepoctest.go > sdk/trace/safetruncatepoctest.go cd sdk go test ./trace -run TestSafeTruncateBypass -count=1 -v

Expected vulnerable output includes a failing test showing that the returned value exceeds the configured limit: text === RUN TestSafeTruncateBypass safetruncatepoctest.go:14: inputlen=27 gotlen=27 input="AAAA�BBBBBBBBBBBBBBBBBBBB" got="AAAA�BBBBBBBBBBBBBBBBBBBB" safetruncatepoctest.go:16: bypass: gotlen 27 > limit 5 --- FAIL: TestSafeTruncateBypass

The artifact also records the standalone UTF-8 behavior needed for the bypass: sh tar -xOf /path/to/validation-artifact.tar safetruncatebypass/runecheckoutput.txt

Expected output: text r=U+FFFD size=3 runeError=true

Impact

This is a Unicode handling and resource-limit bypass that weakens span attribute memory controls. Applications that enable AttributeValueLengthLimit to bound memory usage can still store oversized attacker-controlled attribute values if those values contain U+FFFD. The practical impact is increased memory use and reduced denial-of-service protection in the instrumented process; the finding does not show confidentiality or integrity impact.

Affected Software

1 affected componentFixes available
go/go.opentelemetry.io/otel/sdk>=1.10.0<1.33.0
1.33.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/go.opentelemetry.io/otel/sdk to a version that resolves this vulnerability.

    Fixed in 1.33.0

Event History

Sep 29, 2026
Advisory Published
via GitHub·05:59 PM
Data Sourced
via GitHub·05:59 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Exposure requires AttributeValueLengthLimit to be enabled with a non-negative value and application-controlled span attributes to contain attacker-controlled data. Deployments without attribute value length limits enabled are not affected by this specific limit-bypass condition.

2

What input is needed to trigger the bypass?

An attacker-controlled string attribute, or an entry in a string-slice attribute, must exceed the configured limit and include the valid Unicode replacement character U+FFFD. Under those conditions, the value can be retained without truncation, increasing per-span memory use.

3

Which span attribute types follow the affected path?

The identified truncation path applies to string attributes and to individual entries of string-slice attributes. Other attribute types are not identified in the provided evidence as using the affected path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203