Skip to content

[SECURITY] Update Rust crate opentelemetry_sdk to 0.33.0 [SECURITY] - #2020

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/crate-opentelemetry_sdk-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/crate-opentelemetry_sdk-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
opentelemetry_sdk (source) dependencies minor 0.32.0 → 0.33.0

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

CVE-2026-48504 / GHSA-w9wp-h8wv-79jx

More information

Details

Summary

BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce the W3C Baggage size limits before parsing an inbound baggage header. A large attacker-controlled header could cause unnecessary CPU work and short-lived heap allocations while parsing entries that would later be discarded by the SDK's baggage storage limits.

The SDK now applies limits aligned with the W3C Baggage limits:

  • 64 list-members
  • 8192 bytes total
Impact

Services that accept untrusted inbound propagation headers may experience increased per-request resource usage when processing oversized baggage headers. This can contribute to denial-of-service risk, especially when application or transport-level header limits are absent or configured above the W3C Baggage limits.

The impact is limited to availability. This issue does not expose telemetry data, modify telemetry data, or allow code execution.

Patches

Upgrade opentelemetry_sdk to version 0.32.1 or later.

Version 0.32.1 rejects baggage header values larger than 8192 bytes and limits extraction to the first 64 list-members.

Workarounds

If upgrading immediately is not possible, reject or limit inbound baggage headers larger than 8192 bytes before invoking OpenTelemetry propagation extraction. This can be enforced at a proxy, gateway, middleware layer, or custom carrier boundary.

Resources
Credit

tonghuaroot

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

open-telemetry/opentelemetry-rust (opentelemetry_sdk)

v0.33.0

Released 2026-Sep-18

  • Publicly export the OTEL_*/OTEL_*_DEFAULT environment variable name and
    default value constants for BatchSpanProcessor (opentelemetry_sdk::trace),
    BatchLogProcessor (opentelemetry_sdk::logs), and PeriodicReader
    (opentelemetry_sdk::metrics), so downstream configuration systems can read
    the SDK's spec-defined defaults programmatically instead of duplicating
    them. As part of this, PeriodicReader's previously-private
    DEFAULT_INTERVAL/METRIC_EXPORT_INTERVAL_NAME constants were renamed
    to OTEL_METRIC_EXPORT_INTERVAL_DEFAULT/OTEL_METRIC_EXPORT_INTERVAL to
    match the naming convention already used elsewhere.
    (#​3623)
  • Added SDK self-observability metrics, feature-gated behind
    experimental_metrics_bound_instruments: otel.sdk.log.created counts log
    records submitted to the SDK; otel.sdk.processor.log.processed and
    otel.sdk.processor.span.processed count records and spans submitted to an
    exporter by batch and simple processors, with error.type reporting items
    dropped before submission; and otel.sdk.processor.log.queue.capacity
    reports the configured BatchLogProcessor queue capacity.
    (#​3514,
    #​3608,
    #​3609,
    #​3611)
  • Made futures-channel, futures-executor, futures-util, and thiserror
    optional, enabling a minimal SDK build. With default-features = false, the
    SDK's only dependency is the opentelemetry API crate.
    (#​3593)
  • Bound instruments are now available for Gauge and UpDownCounter via the
    new BoundGauge<T> and BoundUpDownCounter<T> types exposed by the
    opentelemetry crate. Requires the experimental_metrics_bound_instruments
    feature.
  • Fixed a race in BatchSpanProcessor and BatchLogProcessor where a
    span/log enqueued just before force_flush() or shutdown() could be
    missed by the flush and dropped at shutdown: the pending-item counter is
    now incremented before enqueueing (and reverted if the queue is full), so
    the worker's counter snapshot can no longer under-count items already in
    the queue (#​3453).
  • Default SDK Resource construction now falls back to unknown_service under
    Miri instead of calling std::env::current_exe(), avoiding an abort in Miri
    isolation mode while preserving the normal
    unknown_service:<process.executable.name> fallback outside Miri.
  • Fixed asynchronous counters (ObservableCounter, ObservableUpDownCounter)
    using delta temporality reporting incorrect deltas when observed attributes
    were recorded in an unsorted key order.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/crate-opentelemetry_sdk-vulnerability branch 3 times, most recently from 3dc4c41 to a1e761b Compare October 3, 2026 18:13
@renovate
renovate Bot force-pushed the renovate/crate-opentelemetry_sdk-vulnerability branch from a1e761b to c91d808 Compare October 3, 2026 18:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants