THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-29181 (HIGH 7.5) — OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many bagg

[NVD] CVE-2026-29181 (HIGH 7.5) — OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many bagg

lownvdPublished 2026-04-07

CVE-2026-29181 CVSS: 7.5 HIGH Published: 2026-04-07T21:17:16.003

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-29181