CVE-2026-81872: CPU Exhaustion via Tight Loop in OpenTelemetry-Go BatchingProcessor
Vulnerability ID: CVE-2026-81872
CVSS Score: 6.3
Published: 2026-09-29
An uncontrolled resource consumption vulnerability in the logs SDK of OpenTelemetry-Go allows remote attackers to trigger a denial of service. Under conditions of downstream exporter backpressure, the BatchingProcessor enters a tight loop, exhausting CPU resources. This occurs because the processor immediately schedules retry attempts without waiting for its ticker interval, spinning continuously when the internal queue remains filled above the batch size. The issue affects all versions prior to v0.21.0 of the go.opentelemetry.io/otel/sdk/log package.
TL;DR
A high-severity CPU exhaustion vulnerability in OpenTelemetry-Go's logging SDK allows remote attackers to cause a denial of service via tight-loop execution when downstream exporters experience backpressure.
Technical Details
- CWE ID: CWE-400 (Uncontrolled Resource Consumption), CWE-834 (Excessive Iteration)
- Attack Vector: Network (AV:N)
- CVSS Score: 6.3 (Medium)
- EPSS Score: 0.00524 (Percentile: 42.16%)
- Impact: Denial of Service / CPU Exhaustion
- Exploit Status: No weaponized exploits exist in the wild
- KEV Status: Not listed in CISA KEV
Affected Systems
- Applications running Go services utilizing the OpenTelemetry-Go SDK logs package (go.opentelemetry.io/otel/sdk/log)
-
go.opentelemetry.io/otel/sdk/log: < v0.21.0 (Fixed in:
v0.21.0)
Code Analysis
Commit: ba71b09
Fix CPU exhaustion in BatchingProcessor by removing the polling goroutine and processing events synchronously.
Mitigation Strategies
- Upgrade OpenTelemetry-Go logs SDK to version v0.21.0 or higher
- Implement strict timeout limits on logging exporters to prevent prolonged backpressure
- Establish CPU usage alerts on logging microservices to detect abnormal spikes
Remediation Steps:
- Identify vulnerable dependencies within the Go module files using scanning tools
- Update the go.mod dependency: go get go.opentelemetry.io/otel/sdk/log@v0.21.0
- Run go mod tidy to clean up dependency configurations
- Recompile the application and redeploy to production environments
References
- Official CVE Record
- NVD Entry
- GitHub Security Advisory
- GitHub Official Pull Request
- Official Fix Commit
- Issue Tracker Discussion
- Vulnerable Component Release Tag
- Wiz Vulnerability Database
Read the full report for CVE-2026-81872 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)