opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics
CVE-2023-43810
7.5HIGH
What is CVE-2023-43810?
OpenTelemetry, an open-source observability framework, is affected by a vulnerability that stems from unbound cardinality in the http_method label during autoinstrumentation. Attackers can exploit this flaw by sending numerous malicious requests with random and extended HTTP methods, potentially leading to memory exhaustion on the server. This issue arises when there is a lack of filtering for unknown HTTP methods at various layers, such as CDNs or load balancers. The vulnerability has been addressed in version 0.41b0.
Affected Version(s)
opentelemetry-python-contrib < 0.41b0
