{"id":"CVE-2023-25151","aliases":["GHSA-5r5m-65gx-7vrh","GO-2023-1546"],"url":"https://o3.security/vulnerability/CVE-2023-25151","summary":"DoS vulnerability for high cardinality metrics in opentelemetry-go-contrib","details":"opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` uses the `httpconv.ServerRequest` function to annotate metric measurements for the `http.server.request_content_length`, `http.server.response_content_length`, and `http.server.duration` instruments. The `ServerRequest` function sets the `http.target` attribute value to be the whole request URI (including the query string)[^1]. The metric instruments do not \"forget\" previous measurement attributes when `cumulative` temporality is used, this means the cardinality of the measurements allocated is directly correlated with the unique URIs handled. If the query string is constantly random, this will result in a constant increase in memory allocation that can be used in a denial-of-service attack. This issue has been addressed in version 0.39.0. Users are advised to upgrade. There are no known workarounds for this issue.","published":"2023-02-08T19:21:37.401Z","modified":"2026-08-12T03:51:14.116225969Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00973,"percentile":0.58888,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp","fixedVersion":"0.39.0"},{"ecosystem":"Go","name":"go.opentelemetry.io/contrib/instrumentation/github.com/astaxie/beego/otelbeego","fixedVersion":"0.39.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/open-telemetry/opentelemetry-go/blob/v1.12.0/semconv/internal/v2/http.go#L159"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25151.json"},{"type":"ADVISORY","url":"https://github.com/open-telemetry/opentelemetry-go-contrib/security/advisories/GHSA-5r5m-65gx-7vrh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25151"},{"type":"PACKAGE","url":"https://github.com/open-telemetry/opentelemetry-go-contrib"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:14.116225969Z"}}