GHSA-5wrp-cwcj-q835
MODERATECVE-2026-41178https://github.com/open-telemetry/opentelemetry-go/pull/7880 removed raw-length rejection and it causes Parse to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs.
- Affected
- >=1.41.0, <1.42.0, >=1.43.0, <1.44.0
- Fixed in
- 1.42.0
- Weakness
- CWE-789
- Published
- 2026-05-28
- Source
- osv