CVE-2024-36129

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-36129
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-36129.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-36129
Aliases
Downstream
Related
Published
2024-06-05T17:26:13.903Z
Modified
2025-11-28T02:34:28.132640Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
OpenTelemetry Collector has a Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC
Details

The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36129.json",
    "cwe_ids": [
        "CWE-119"
    ]
}
References

Affected packages

Git / github.com/open-telemetry/opentelemetry-collector

Affected ranges

Type
GIT
Repo
https://github.com/open-telemetry/opentelemetry-collector
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed