go package report

Is go.opentelemetry.io/otel/schema/v1.0 safe?

1 known vulnerability, worst severity LOW.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


      cvss
      0.0
      low

      severity out of 10

      epss
      0.00%
      low

      chance of exploitation in 30 days, 6th percentile of all CVEs

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-995v-fvrw-c78m, the advisory selected below

      // 1 advisories

      GHSA-995v-fvrw-c78m

      LOWCVE-2026-45287
      // summary

      go.opentelemetry.io/otel/schema/v1.0 and go.opentelemetry.io/otel/schema/v1.1 leaks one file descriptor on each successful ParseFile call. ParseFile opens the schema file and passes it to Parse without closing it; repeated parsing in a long-running process can exhaust the process file descriptor limit and cause denial of service. The severity is low because exploitation depends on a consuming application exposing repeated schema parsing to an attacker-controlled path.

      Introduced in commit: e72a235

      // details

      In schema/v1.0/parser.go:41-47, ParseFile opens the requested schema path with os.Open and then returns Parse(file) without a defer file.Close() or other close path:

      file, err := os.Open(schemaFilePath)
      if err != nil {
      	return nil, err
      }
      return Parse(file)

      The validation evidence also identifies schema/v1.0/parser.go:50-73: Parse accepts an io.Reader, decodes from it, and does not close it. Ownership of the opened file is therefore not transferred to Parse, leaving the descriptor open until the Go runtime eventually finalizes the file object. With repeated ParseFile calls, descriptors can accumulate until the process receives EMFILE / "too many open files".

      // poc

      validation-artifact.zip

      The local artifact validation-artifact.zip contains:

      • leakpoc.go: PoC source that repeatedly calls schema.ParseFile("schema/v1.0/testdata/valid-example.yaml") and prints /proc/self/fd counts.
      • LEAKPOCREADME.txt: reproduction notes.
      • leakpocrun.log: captured attempted run; the local offline environment failed before execution because Go module download from proxy.golang.org was forbidden.

      Reproduce from the root of a checkout of pellared/opentelemetry-go at commit e72a235 with Go module dependencies already available:

      /bin/sh -c 'ulimit -n 256; GOGC=off go run leak_poc.go'

      Configuration:

      • File descriptor soft limit: 256
      • Garbage collection: disabled with GOGC=off so leaked descriptors are not reclaimed during the loop
      • Schema file: schema/v1.0/testdata/valid-example.yaml

      Expected output is increasing descriptor counts followed by an EMFILE failure, for example:

      iter 0 fds 7
      iter 50 fds 57
      iter 100 fds 107
      ...
      panic: iteration 248: open schema/v1.0/testdata/valid-example.yaml: too many open files

      The exact initial descriptor count and failing iteration can vary by OS and process state.

      // impact

      This is a file descriptor resource leak leading to availability loss. Applications that call schema.ParseFile repeatedly, especially through a runtime reload or request-controlled path, can exhaust their process file descriptor table and fail subsequent file, socket, or other descriptor operations. Impact is limited to denial of service of the consuming process; the evidence does not show confidentiality or integrity impact.

      // cvss v4.0 vector

      CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

      Attack vector
      Local
      Attack complexity
      Low
      Attack requirements
      Present
      Privileges required
      None
      User interaction
      None
      Confidentiality (vulnerable system)
      None
      Integrity (vulnerable system)
      None
      Availability (vulnerable system)
      Low
      Confidentiality (subsequent systems)
      None
      Integrity (subsequent systems)
      None
      Availability (subsequent systems)
      None

      Checked 2026-09-26 at 01:06 UTC. The most recent advisory here was published 2026-05-28. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.