Disclosure summary
### Summary The OpenTelemetry Go SDK trace package can fail to enforce `AttributeValueLengthLimit` for string attributes containing the valid Unicode replacement character U+FFFD. An oversized attacker-controlled attribute value that includes U+FFFD is returned untruncated, bypassing the configured memory/DoS protection and allowing increased per-span memory usage. The finding is low severity because it requires a deployment with attribute value length limits enabled and attacker-controlled data being recorded into span attributes. Introduced in commit 49a6536 ### Details String and string-slice span attributes are truncated through `safeTruncate` when `AttributeValueLengthLimit` is non-negative. The finding evidence identifies this enforcement path in `sdk/trace/span.go:303-331`, with string attributes passed to `safeTruncate` at `sdk/trace/span.go:309-310` and string-slice entries passed to `safeTruncate` in the loop beginning at `sdk/trace/span.go:312`. `safeTruncate` first calls `safeTruncateValidUTF8`; if that returns `ok=false`, it calls `strings.ToValidUTF8(input, "")` and retries. The relevant code is identified in `sdk/trace/span.go:337-355`. `safeTruncateValidUTF8` treats
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-p9f8-wvj8-2fg8
Open original source · Updated Sep 29, 2026
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
Source severity: MEDIUM / 5.1
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | go.opentelemetry.io/otel/sdk | >= 1.10.0, < 1.33.0 | 1.33.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-29T13:59:10-04:00
MODIFIED 2026-09-29T13:59:11-04:00
INGESTED 2026-10-06T11:43:08-04:00