{"id":"DEBIAN-CVE-2026-81869","details":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing the valid Unicode replacement character U+FFFD. safeTruncateValidUTF8 treats the valid replacement rune as invalid UTF-8 and returns the original input, while strings.ToValidUTF8 leaves that valid rune unchanged, so a second safeTruncate attempt can also return the oversized value. An attacker who controls span attribute content can retain values longer than the configured limit, increasing per-span memory use and weakening denial-of-service protection in the instrumented process. This issue is fixed in version 1.33.0.","modified":"2026-10-06T10:06:36.592381340Z","published":"2026-09-16T21:17:22.180Z","upstream":["CVE-2026-81869"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-81869"}],"affected":[{"package":{"name":"golang-opentelemetry-otel","ecosystem":"Debian:13","purl":"pkg:deb/debian/golang-opentelemetry-otel?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.31.0-4","1.31.0-5","1.31.0-6","1.43.0-1","1.43.0-2","1.43.0-3","1.43.0-4","1.46.0-1~exp1","1.46.0-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-81869.json"}},{"package":{"name":"golang-opentelemetry-otel","ecosystem":"Debian:14","purl":"pkg:deb/debian/golang-opentelemetry-otel?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.43.0-1"}]}],"versions":["1.31.0-4","1.31.0-5","1.31.0-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-81869.json"}}],"schema_version":"1.9.0"}