An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption.
{ "url": "https://pkg.go.dev/vuln/GO-2024-2900", "review_status": "REVIEWED" }
{ "imports": [ { "symbols": [ "ClientConfig.ToClientConn", "getGRPCCompressionName" ], "path": "go.opentelemetry.io/collector/config/configgrpc" } ] }
{ "imports": [ { "symbols": [ "ServerConfig.ToServer", "clientInfoHandler.ServeHTTP", "decompressor.ServeHTTP", "httpContentDecompressor" ], "path": "go.opentelemetry.io/collector/config/confighttp" } ] }