Report: Latest: CVE-2026-29181 - OpenTelemetry-Go multi-value `baggage` header extraction causes excessive alloca...

Report: Latest: CVE-2026-29181 - OpenTelemetry-Go multi-value `baggage` header extraction causes excessive alloca...

CVE ID :CVE-2026-29181 Published : April 7, 2026, 9:17 p.m. | 36 minutes ago Description :OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
April 7, 2026