AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-81869.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 5.1CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

### Summary The OpenTelemetry Go SDK trace package can fail to enforce `AttributeValueLengthLimit` for string attributes containing the valid Unicode replacement character U+FFFD. An oversized attacker-controlled attribute value that includes U+FFFD is returned untruncated, bypassing the configured memory/DoS protection and allowing increased per-span memory usage. The finding is low severity because it requires a deployment with attribute value length limits enabled and attacker-controlled data being recorded into span attributes. Introduced in commit 49a6536 ### Details String and string-slice span attributes are truncated through `safeTruncate` when `AttributeValueLengthLimit` is non-negative. The finding evidence identifies this enforcement path in `sdk/trace/span.go:303-331`, with string attributes passed to `safeTruncate` at `sdk/trace/span.go:309-310` and string-slice entries passed to `safeTruncate` in the loop beginning at `sdk/trace/span.go:312`. `safeTruncate` first calls `safeTruncateValidUTF8`; if that returns `ok=false`, it calls `strings.ToValidUTF8(input, "")` and retries. The relevant code is identified in `sdk/trace/span.go:337-355`. `safeTruncateValidUTF8` treats

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-p9f8-wvj8-2fg8

Open original source · Updated Sep 29, 2026

OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation

Source severity: MEDIUM / 5.1

EcosystemPackageAffected rangeFirst patched
gogo.opentelemetry.io/otel/sdk>= 1.10.0, < 1.33.01.33.0

Original records & references

PUBLISHED 2026-09-29T13:59:10-04:00
MODIFIED 2026-09-29T13:59:11-04:00
INGESTED 2026-10-06T11:43:08-04:00