BIT-opentelemetry-collector-2024-36129

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/opentelemetry-collector/BIT-opentelemetry-collector-2024-36129.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-opentelemetry-collector-2024-36129
Aliases
Published
2025-11-10T17:44:52.258Z
Modified
2025-11-10T18:27:25.094130Z
Summary
OpenTelemetry Collector has a Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC
Details

The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.

Database specific
{
    "severity": "High",
    "cpes": [
        "cpe:2.3:a:opentelemetry:opentelemetry_collector:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / opentelemetry-collector

Package

Name
opentelemetry-collector
Purl
pkg:bitnami/opentelemetry-collector

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.102.1