GHSA-p9f8-wvj8-2fg8: Go/go.opentelemetry.io/otel/sdk vulnerability
Summary
The OpenTelemetry Go SDK trace package can fail to enforce AttributeValueLengthLimit for string attributes containing the valid Unicode replacement character U+FFFD. An oversized attacker-controlled attribute value that includes U+FFFD is returned untruncated, bypassing the configured memory/DoS protection and allowing increased per-span memory usage. The finding is low severity because it requires a deployment with attribute value length limits enabled and attacker-controlled data being recorded into span attributes.
Introduced in commit 49a6536
Details
String and string-slice span attributes are truncated through safeTruncate when AttributeValueLengthLimit is non-negative. The finding evidence identifies this enforcement path in sdk/trace/span.go:303-331, with string attributes passed to safeTruncate at sdk/trace/span.go:309-310 and string-slice entries passed to safeTruncate in the loop beginning at sdk/trace/span.go:312.
safeTruncate first calls safeTruncateValidUTF8; if that returns ok=false, it calls strings.ToValidUTF8(input, "") and retries. The relevant code is identified in sdk/trace/span.go:337-355. safeTruncateValidUTF8 treats any utf8.RuneError from utf8.DecodeRuneInString as invalid UTF-8 and immediately returns the original input with ok=false. However, Go also returns utf8.RuneError for a valid encoded U+FFFD rune. The validation artifact confirms this behavior with output r=U+FFFD size=3 runeError=true.
For an input such as "AAAA" + U+FFFD + strings.Repeat("B", 20) and a limit of 5, the first truncation attempt sees U+FFFD as utf8.RuneError and returns the full input with ok=false. strings.ToValidUTF8 does not remove the valid U+FFFD rune, so the second attempt returns the same full input. As a result, the span attribute value remains 27 bytes long even though the configured limit is 5.
PoC
validation-artifact.zip
The validation artifact contains a package-level Go test at validation-artifact.tar:safetruncatebypass/safetruncatepoctest.go and supporting output at validation-artifact.tar:safetruncatebypass/runecheckoutput.txt.
Reproduction configuration: - Repository: pellared/opentelemetry-go - Commit: 49a6536 from September 12, 2022 - Package/module path: sdk/trace under the sdk module - Attribute value length limit used by the PoC: limit := 5 - Dependencies must be available through the network or a local module cache/vendor directory.
Commands: sh cd /path/to/opentelemetry-go git checkout 49a6536 tar -xOf /path/to/validation-artifact.tar safetruncatebypass/safetruncatepoctest.go > sdk/trace/safetruncatepoctest.go cd sdk go test ./trace -run TestSafeTruncateBypass -count=1 -v
Expected vulnerable output includes a failing test showing that the returned value exceeds the configured limit: text === RUN TestSafeTruncateBypass safetruncatepoctest.go:14: inputlen=27 gotlen=27 input="AAAA�BBBBBBBBBBBBBBBBBBBB" got="AAAA�BBBBBBBBBBBBBBBBBBBB" safetruncatepoctest.go:16: bypass: gotlen 27 > limit 5 --- FAIL: TestSafeTruncateBypass
The artifact also records the standalone UTF-8 behavior needed for the bypass: sh tar -xOf /path/to/validation-artifact.tar safetruncatebypass/runecheckoutput.txt
Expected output: text r=U+FFFD size=3 runeError=true
Impact
This is a Unicode handling and resource-limit bypass that weakens span attribute memory controls. Applications that enable AttributeValueLengthLimit to bound memory usage can still store oversized attacker-controlled attribute values if those values contain U+FFFD. The practical impact is increased memory use and reduced denial-of-service protection in the instrumented process; the finding does not show confidentiality or integrity impact.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/go.opentelemetry.io/otel/sdkto a version that resolves this vulnerability.Fixed in 1.33.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Exposure requires AttributeValueLengthLimit to be enabled with a non-negative value and application-controlled span attributes to contain attacker-controlled data. Deployments without attribute value length limits enabled are not affected by this specific limit-bypass condition.
What input is needed to trigger the bypass?
An attacker-controlled string attribute, or an entry in a string-slice attribute, must exceed the configured limit and include the valid Unicode replacement character U+FFFD. Under those conditions, the value can be retained without truncation, increasing per-span memory use.
Which span attribute types follow the affected path?
The identified truncation path applies to string attributes and to individual entries of string-slice attributes. Other attribute types are not identified in the provided evidence as using the affected path.