GHSA-5r5m-65gx-7vrh
HIGHCVE-2023-25151The [v0.38.0](https://github.com/open-telemetry/opentelemetry-go-contrib/releases/tag/v1.13.0) release of [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/463c2e7cd69d25f40b0a595b05394eeb26c68ae2/instrumentation/net/http/otelhttp/handler.go#L218) uses the [httpconv.ServerRequest](https://github.com/open-telemetry/opente
- Affected
- >= 0.38.0, < 0.39.0
- Fixed in
- 0.39.0
- Weakness
- CWE-400
- Published
- 2023-02-08
- Source
- github