{"schema_version":"1.7.3","id":"GHSA-5r5m-65gx-7vrh","published":"2023-02-08T22:32:16Z","modified":"2026-02-04T04:31:19.108693Z","aliases":["CVE-2023-25151","GO-2023-1546"],"related":["CVE-2023-45142","GO-2022-0322","GO-2023-2113"],"summary":"otelhttp and otelbeego have DoS vulnerability for high cardinality metrics","details":"### Impact\n\nThe [v0.38.0](https://github.com/open-telemetry/opentelemetry-go-contrib/releases/tag/v1.13.0) release of [`go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp`](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/463c2e7cd69d25f40b0a595b05394eeb26c68ae2/instrumentation/net/http/otelhttp/handler.go#L218) uses the [`httpconv.ServerRequest`](https://github.com/open-telemetry/opentelemetry-go/blob/v1.12.0/semconv/internal/v2/http.go#L159) function to annotate metric measurements for the `http.server.request_content_length`, `http.server.response_content_length`, and `http.server.duration` instruments.\n\nThe `ServerRequest` function sets the `http.target` attribute value to be the whole request URI (including the query string)[^1]. The metric instruments do not \"forget\" previous measurement attributes when `cumulative` temporality is used, this means the cardinality of the measurements allocated is directly correlated with the unique URIs handled. If the query string is constantly random, this will result in a constant increase in memory allocation that can be used in a denial-of-service attack.\n\nPseudo-attack:\n```\nfor infinite loop {\n  r := generate_random_string()\n  do_http_request(\"/some/path?random=\"+r)\n}\n```\n\n### Patches\n- `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` - v0.39.0\n- `go.opentelemetry.io/contrib/instrumentation/github.com/astaxie/beego/otelbeego` - v0.39.0\n\n[^1]: https://github.com/open-telemetry/opentelemetry-go/blob/6cb5718eaaed5c408c3bf4ad1aecee5c20ccdaa9/semconv/internal/v2/http.go#L202-L208","affected":[{"package":{"name":"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp","ecosystem":"Go","purl":"pkg:golang/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.38.0"},{"fixed":"0.39.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-5r5m-65gx-7vrh/GHSA-5r5m-65gx-7vrh.json"}},{"package":{"name":"go.opentelemetry.io/contrib/instrumentation/github.com/astaxie/beego/otelbeego","ecosystem":"Go","purl":"pkg:golang/go.opentelemetry.io/contrib/instrumentation/github.com/astaxie/beego/otelbeego"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.38.0"},{"fixed":"0.39.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-5r5m-65gx-7vrh/GHSA-5r5m-65gx-7vrh.json"}}],"references":[{"type":"WEB","url":"https://github.com/open-telemetry/opentelemetry-go-contrib/security/advisories/GHSA-5r5m-65gx-7vrh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25151"},{"type":"PACKAGE","url":"https://github.com/open-telemetry/opentelemetry-go-contrib"},{"type":"WEB","url":"https://github.com/open-telemetry/opentelemetry-go/blob/v1.12.0/semconv/internal/v2/http.go#L159"}],"database_specific":{"cwe_ids":["CWE-400"],"github_reviewed":true,"github_reviewed_at":"2023-02-08T22:32:16Z","nvd_published_at":"2023-02-08T20:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}