GHSA-995v-fvrw-c78m

Suggest an improvement
Source
https://github.com/advisories/GHSA-995v-fvrw-c78m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-995v-fvrw-c78m/GHSA-995v-fvrw-c78m.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-995v-fvrw-c78m
Aliases
Downstream
MINI (6)
Published
2026-05-28T17:19:10Z
Modified
2026-07-15T22:00:55Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
opentelemetry-go's Schema ParseFile leaks file descriptors on each parse
Details

Summary

go.opentelemetry.io/otel/schema/v1.0 and go.opentelemetry.io/otel/schema/v1.1 leaks one file descriptor on each successful ParseFile call. ParseFile opens the schema file and passes it to Parse without closing it; repeated parsing in a long-running process can exhaust the process file descriptor limit and cause denial of service. The severity is low because exploitation depends on a consuming application exposing repeated schema parsing to an attacker-controlled path.

Introduced in commit: e72a235

Details

In schema/v1.0/parser.go:41-47, ParseFile opens the requested schema path with os.Open and then returns Parse(file) without a defer file.Close() or other close path:

file, err := os.Open(schemaFilePath)
if err != nil {
	return nil, err
}
return Parse(file)

The validation evidence also identifies schema/v1.0/parser.go:50-73: Parse accepts an io.Reader, decodes from it, and does not close it. Ownership of the opened file is therefore not transferred to Parse, leaving the descriptor open until the Go runtime eventually finalizes the file object. With repeated ParseFile calls, descriptors can accumulate until the process receives EMFILE / "too many open files".

PoC

validation-artifact.zip

The local artifact validation-artifact.zip contains:

  • leak_poc.go: PoC source that repeatedly calls schema.ParseFile("schema/v1.0/testdata/valid-example.yaml") and prints /proc/self/fd counts.
  • LEAK_POC_README.txt: reproduction notes.
  • leak_poc_run.log: captured attempted run; the local offline environment failed before execution because Go module download from proxy.golang.org was forbidden.

Reproduce from the root of a checkout of pellared/opentelemetry-go at commit e72a235 with Go module dependencies already available:

/bin/sh -c 'ulimit -n 256; GOGC=off go run leak_poc.go'

Configuration:

  • File descriptor soft limit: 256
  • Garbage collection: disabled with GOGC=off so leaked descriptors are not reclaimed during the loop
  • Schema file: schema/v1.0/testdata/valid-example.yaml

Expected output is increasing descriptor counts followed by an EMFILE failure, for example:

iter 0 fds 7
iter 50 fds 57
iter 100 fds 107
...
panic: iteration 248: open schema/v1.0/testdata/valid-example.yaml: too many open files

The exact initial descriptor count and failing iteration can vary by OS and process state.

Impact

This is a file descriptor resource leak leading to availability loss. Applications that call schema.ParseFile repeatedly, especially through a runtime reload or request-controlled path, can exhaust their process file descriptor table and fail subsequent file, socket, or other descriptor operations. Impact is limited to denial of service of the consuming process; the evidence does not show confidentiality or integrity impact.

Database specific
{
    "cwe_ids": [
        "CWE-772",
        "CWE-775"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-28T17:19:10Z",
    "nvd_published_at": "2026-06-04T16:16:38Z",
    "severity": "LOW"
}
References

Affected packages

Go
go.opentelemetry.io/otel/schema/v1.1

Package

Name
go.opentelemetry.io/otel/schema/v1.1
View open source insights on deps.dev
Purl
pkg:golang/go.opentelemetry.io/otel/schema/v1.1

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.17

Database specific

last_known_affected_version_range
"<= 0.0.16"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-995v-fvrw-c78m/GHSA-995v-fvrw-c78m.json"
go.opentelemetry.io/otel/schema/v1.0

Package

Name
go.opentelemetry.io/otel/schema/v1.0
View open source insights on deps.dev
Purl
pkg:golang/go.opentelemetry.io/otel/schema/v1.0

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.17

Database specific

last_known_affected_version_range
"<= 0.0.16"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-995v-fvrw-c78m/GHSA-995v-fvrw-c78m.json"
go.opentelemetry.io/otel/schema

Package

Name
go.opentelemetry.io/otel/schema
View open source insights on deps.dev
Purl
pkg:golang/go.opentelemetry.io/otel/schema

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.17

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-995v-fvrw-c78m/GHSA-995v-fvrw-c78m.json"