CWE-834
DiscouragedExcessive Iteration
Abstraction: Class · Status: Incomplete
The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.
146 vulnerabilities reference this CWE, most recent first.
GHSA-GR25-JP8F-W3C7
Vulnerability from github – Published: 2022-05-13 01:42 – Updated: 2022-05-13 01:42The ReadRLEImage function in coders\rle.c in ImageMagick 7.0.6-1 has a large loop vulnerability via a crafted rle file that triggers a huge number_pixels value.
{
"affected": [],
"aliases": [
"CVE-2017-11360"
],
"database_specific": {
"cwe_ids": [
"CWE-834"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-07-17T13:18:00Z",
"severity": "MODERATE"
},
"details": "The ReadRLEImage function in coders\\rle.c in ImageMagick 7.0.6-1 has a large loop vulnerability via a crafted rle file that triggers a huge number_pixels value.",
"id": "GHSA-gr25-jp8f-w3c7",
"modified": "2022-05-13T01:42:16Z",
"published": "2022-05-13T01:42:16Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-11360"
},
{
"type": "WEB",
"url": "https://github.com/ImageMagick/ImageMagick/issues/518"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-GR3R-235R-P35C
Vulnerability from github – Published: 2022-05-13 01:52 – Updated: 2022-05-13 01:52libimageworsener.a in ImageWorsener 1.3.2, when libjpeg 8d is used, has a large loop in the get_raw_sample_int function in imagew-main.c.
{
"affected": [],
"aliases": [
"CVE-2018-5252"
],
"database_specific": {
"cwe_ids": [
"CWE-834"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2018-01-05T21:29:00Z",
"severity": "MODERATE"
},
"details": "libimageworsener.a in ImageWorsener 1.3.2, when libjpeg 8d is used, has a large loop in the get_raw_sample_int function in imagew-main.c.",
"id": "GHSA-gr3r-235r-p35c",
"modified": "2022-05-13T01:52:45Z",
"published": "2022-05-13T01:52:45Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5252"
},
{
"type": "WEB",
"url": "https://github.com/jsummers/imageworsener/issues/34"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-H246-95J7-6PM6
Vulnerability from github – Published: 2022-05-13 01:43 – Updated: 2022-05-13 01:43In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MOV file, which claims a large "item_count" field in the header but does not contain sufficient backing data, is provided, the loop would consume huge CPU and memory resources, since there is no EOF check inside the loop.
{
"affected": [],
"aliases": [
"CVE-2017-14222"
],
"database_specific": {
"cwe_ids": [
"CWE-834"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-09-09T01:29:00Z",
"severity": "HIGH"
},
"details": "In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MOV file, which claims a large \"item_count\" field in the header but does not contain sufficient backing data, is provided, the loop would consume huge CPU and memory resources, since there is no EOF check inside the loop.",
"id": "GHSA-h246-95j7-6pm6",
"modified": "2022-05-13T01:43:21Z",
"published": "2022-05-13T01:43:21Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-14222"
},
{
"type": "WEB",
"url": "https://github.com/FFmpeg/FFmpeg/commit/9cb4eb772839c5e1de2855d126bf74ff16d13382"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2017/dsa-3996"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/100701"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-H3JW-CRR6-78MF
Vulnerability from github – Published: 2022-05-13 01:27 – Updated: 2022-05-13 01:27In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop. This was addressed in epan/dissectors/packet-bgp.c by validating Path Attribute lengths.
{
"affected": [],
"aliases": [
"CVE-2018-14342"
],
"database_specific": {
"cwe_ids": [
"CWE-834"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2018-07-19T02:29:00Z",
"severity": "HIGH"
},
"details": "In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop. This was addressed in epan/dissectors/packet-bgp.c by validating Path Attribute lengths.",
"id": "GHSA-h3jw-crr6-78mf",
"modified": "2022-05-13T01:27:51Z",
"published": "2022-05-13T01:27:51Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-14342"
},
{
"type": "WEB",
"url": "https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13741"
},
{
"type": "WEB",
"url": "https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=36af43dbb7673495948cd65d0346e8b9812b941c"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2018/07/msg00045.html"
},
{
"type": "WEB",
"url": "https://www.wireshark.org/security/wnpa-sec-2018-34.html"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.html"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/104847"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id/1041608"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-H3RJ-J63V-PP8Q
Vulnerability from github – Published: 2022-05-13 01:47 – Updated: 2022-05-13 01:47The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
{
"affected": [],
"aliases": [
"CVE-2017-9254"
],
"database_specific": {
"cwe_ids": [
"CWE-834"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-06-27T12:29:00Z",
"severity": "HIGH"
},
"details": "The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.",
"id": "GHSA-h3rj-j63v-pp8q",
"modified": "2022-05-13T01:47:51Z",
"published": "2022-05-13T01:47:51Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-9254"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2017/Jun/32"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-H4RG-H5CX-4R4W
Vulnerability from github – Published: 2023-04-12 21:30 – Updated: 2025-11-04 00:30LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
{
"affected": [],
"aliases": [
"CVE-2023-1993"
],
"database_specific": {
"cwe_ids": [
"CWE-834"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-12T21:15:00Z",
"severity": "MODERATE"
},
"details": "LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file",
"id": "GHSA-h4rg-h5cx-4r4w",
"modified": "2025-11-04T00:30:36Z",
"published": "2023-04-12T21:30:19Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1993"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1993.json"
},
{
"type": "WEB",
"url": "https://gitlab.com/wireshark/wireshark/-/issues/18900"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00029.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EHLTD25WNQSPQNELX52UH6YLP4TBLKTT"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FZA7IMATNNQPLIM6WMRPM3T5ZY24NRR2"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PFJERBHVWYLYWXO2B3V47QH66IEB6EZ3"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EHLTD25WNQSPQNELX52UH6YLP4TBLKTT"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FZA7IMATNNQPLIM6WMRPM3T5ZY24NRR2"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PFJERBHVWYLYWXO2B3V47QH66IEB6EZ3"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202309-02"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5429"
},
{
"type": "WEB",
"url": "https://www.wireshark.org/security/wnpa-sec-2023-10.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-H55V-WGPX-C3RF
Vulnerability from github – Published: 2022-05-24 17:34 – Updated: 2024-01-23 15:30A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.5; v3.6 versions prior to 3.6.10. This issue affects: MongoDB Inc. MongoDB Server 3.6 versions prior to 3.6.10; 4.0 versions prior to 4.0.5.
{
"affected": [],
"aliases": [
"CVE-2018-20805"
],
"database_specific": {
"cwe_ids": [
"CWE-834"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2020-11-23T16:15:00Z",
"severity": "MODERATE"
},
"details": "A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.5; v3.6 versions prior to 3.6.10. This issue affects: MongoDB Inc. MongoDB Server 3.6 versions prior to 3.6.10; 4.0 versions prior to 4.0.5.",
"id": "GHSA-h55v-wgpx-c3rf",
"modified": "2024-01-23T15:30:55Z",
"published": "2022-05-24T17:34:47Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20805"
},
{
"type": "WEB",
"url": "https://jira.mongodb.org/browse/SERVER-38164"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-HCJV-F67J-6XG2
Vulnerability from github – Published: 2022-05-13 01:43 – Updated: 2022-05-13 01:43In M3UParser::parse of M3UParser.cpp, there is a memory resource exhaustion due to a large loop of pushing items into a vector. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68399439.
{
"affected": [],
"aliases": [
"CVE-2017-13279"
],
"database_specific": {
"cwe_ids": [
"CWE-834"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2018-04-04T16:29:00Z",
"severity": "MODERATE"
},
"details": "In M3UParser::parse of M3UParser.cpp, there is a memory resource exhaustion due to a large loop of pushing items into a vector. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68399439.",
"id": "GHSA-hcjv-f67j-6xg2",
"modified": "2022-05-13T01:43:09Z",
"published": "2022-05-13T01:43:09Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13279"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2018-04-01"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-HHCP-V65W-C4P9
Vulnerability from github – Published: 2022-05-13 01:47 – Updated: 2022-05-13 01:47The mp4ff_read_ctts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
{
"affected": [],
"aliases": [
"CVE-2017-9257"
],
"database_specific": {
"cwe_ids": [
"CWE-834"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-06-27T12:29:00Z",
"severity": "HIGH"
},
"details": "The mp4ff_read_ctts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.",
"id": "GHSA-hhcp-v65w-c4p9",
"modified": "2022-05-13T01:47:52Z",
"published": "2022-05-13T01:47:52Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-9257"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2017/Jun/32"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-HJF4-FPHR-2H65
Vulnerability from github – Published: 2026-09-29 17:59 – Updated: 2026-09-29 17:59Summary
A BatchingProcessor in go.opentelemetry.io/otel/sdk/log can enter a tight CPU loop when the asynchronous export buffer is full. Under exporter backpressure, attacker-driven high-volume log emission can keep the queue at or above the batch size, causing repeated immediate export retries and a denial of service through CPU exhaustion.
Introduced in commit: 4af9c20
Details
NewBatchingProcessor wraps the exporter with newBufferExporter(exporter, 1) (sdk/log/batch.go:116-122), so the asynchronous export input can fill quickly when the downstream exporter blocks. The poll goroutine dequeues a batch with b.q.TryDequeue, calls b.exporter.EnqueueExport(r), and then immediately sends on b.pollTrigger whenever qLen >= b.batchSize (sdk/log/batch.go:129-165).
bufferExporter.EnqueueExport is non-blocking: it sends to e.input if possible and returns false in the default case when the channel is full (sdk/log/exporter.go:221-248). TryDequeue leaves q.len unchanged when the write callback returns false (sdk/log/batch.go:289-314). Therefore, while the exporter is backpressured, EnqueueExport fails, the queue remains at or above one full batch, and the poll loop continuously retriggers itself without waiting for the ticker.
PoC
The validation artifact contains a PoC bundle:
validation-artifact.tar:main.go: PoC source.validation-artifact.tar:README.md: build/run notes.validation-artifact.tar:build_failed.log: captured build failure from the validation environment.
The PoC configures a blocking exporter and a BatchingProcessor with WithExportMaxBatchSize(1), WithExportInterval(5*time.Second), and WithMaxQueueSize(2048). It emits 1000 records, records a CPU profile for 750 ms while the exporter is blocked, then writes /workspace/validation_artifacts/busyloop.pprof.
Reproduction steps from an affected checkout at commit 4af9c20:
cd /workspace/opentelemetry-go
git checkout 4af9c20
mkdir -p validation_poc/busyloop /workspace/validation_artifacts /tmp/batchingprocessor-busyloop-poc
tar -xf /path/to/this/finding/validation-artifact.tar -C /tmp/batchingprocessor-busyloop-poc
cp /tmp/batchingprocessor-busyloop-poc/main.go validation_poc/busyloop/main.go
go build -o validation_poc/busyloop/busyloop ./validation_poc/busyloop
./validation_poc/busyloop/busyloop
go tool pprof -top /workspace/validation_artifacts/busyloop.pprof
Expected program output:
cpu profile written to /workspace/validation_artifacts/busyloop.pprof
Expected profile evidence: hot functions should include (*BatchingProcessor).poll, (*queue).TryDequeue, and (*bufferExporter).EnqueueExport, showing repeated export attempts while the exporter is blocked.
Impact
This is an availability vulnerability: uncontrolled CPU consumption caused by a busy-spin retry loop. Applications using sdk/log BatchingProcessor are impacted when an attacker can cause sustained log emission and the configured exporter or downstream collector is slow, blocked, or otherwise backpressured. The impact is limited to the embedding process but can degrade or deny service for that application.
{
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "go.opentelemetry.io/otel/sdk/log"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.21.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-81872"
],
"database_specific": {
"cwe_ids": [
"CWE-400",
"CWE-834"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T17:59:53Z",
"nvd_published_at": "2026-09-16T21:17:22Z",
"severity": "MODERATE"
},
"details": "### Summary\n\nA `BatchingProcessor` in `go.opentelemetry.io/otel/sdk/log` can enter a tight CPU loop when the asynchronous export buffer is full. Under exporter backpressure, attacker-driven high-volume log emission can keep the queue at or above the batch size, causing repeated immediate export retries and a denial of service through CPU exhaustion.\n\nIntroduced in commit: 4af9c20\n\n### Details\n\n`NewBatchingProcessor` wraps the exporter with `newBufferExporter(exporter, 1)` (`sdk/log/batch.go:116-122`), so the asynchronous export input can fill quickly when the downstream exporter blocks. The poll goroutine dequeues a batch with `b.q.TryDequeue`, calls `b.exporter.EnqueueExport(r)`, and then immediately sends on `b.pollTrigger` whenever `qLen \u003e= b.batchSize` (`sdk/log/batch.go:129-165`).\n\n`bufferExporter.EnqueueExport` is non-blocking: it sends to `e.input` if possible and returns `false` in the `default` case when the channel is full (`sdk/log/exporter.go:221-248`). `TryDequeue` leaves `q.len` unchanged when the write callback returns `false` (`sdk/log/batch.go:289-314`). Therefore, while the exporter is backpressured, `EnqueueExport` fails, the queue remains at or above one full batch, and the poll loop continuously retriggers itself without waiting for the ticker.\n\n### PoC\n\n[validation-artifact.zip](https://github.com/user-attachments/files/27494002/validation-artifact.zip)\n\nThe validation artifact contains a PoC bundle:\n\n- `validation-artifact.tar:main.go`: PoC source.\n- `validation-artifact.tar:README.md`: build/run notes.\n- `validation-artifact.tar:build_failed.log`: captured build failure from the validation environment.\n\nThe PoC configures a blocking exporter and a `BatchingProcessor` with `WithExportMaxBatchSize(1)`, `WithExportInterval(5*time.Second)`, and `WithMaxQueueSize(2048)`. It emits 1000 records, records a CPU profile for 750 ms while the exporter is blocked, then writes `/workspace/validation_artifacts/busyloop.pprof`.\n\nReproduction steps from an affected checkout at commit `4af9c20`:\n\n```sh\ncd /workspace/opentelemetry-go\ngit checkout 4af9c20\n\nmkdir -p validation_poc/busyloop /workspace/validation_artifacts /tmp/batchingprocessor-busyloop-poc\ntar -xf /path/to/this/finding/validation-artifact.tar -C /tmp/batchingprocessor-busyloop-poc\ncp /tmp/batchingprocessor-busyloop-poc/main.go validation_poc/busyloop/main.go\n\ngo build -o validation_poc/busyloop/busyloop ./validation_poc/busyloop\n./validation_poc/busyloop/busyloop\ngo tool pprof -top /workspace/validation_artifacts/busyloop.pprof\n```\n\nExpected program output:\n\n```text\ncpu profile written to /workspace/validation_artifacts/busyloop.pprof\n```\n\nExpected profile evidence: hot functions should include `(*BatchingProcessor).poll`, `(*queue).TryDequeue`, and `(*bufferExporter).EnqueueExport`, showing repeated export attempts while the exporter is blocked.\n\n\n### Impact\n\nThis is an availability vulnerability: uncontrolled CPU consumption caused by a busy-spin retry loop. Applications using `sdk/log` `BatchingProcessor` are impacted when an attacker can cause sustained log emission and the configured exporter or downstream collector is slow, blocked, or otherwise backpressured. The impact is limited to the embedding process but can degrade or deny service for that application.",
"id": "GHSA-hjf4-fphr-2h65",
"modified": "2026-09-29T17:59:53Z",
"published": "2026-09-29T17:59:53Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hjf4-fphr-2h65"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81872"
},
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-go/issues/6797"
},
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-go/pull/8620"
},
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-go/commit/ba71b09e6ed272e93a669aeaec1e98b1df4cc582"
},
{
"type": "PACKAGE",
"url": "https://github.com/open-telemetry/opentelemetry-go"
},
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/log/v0.21.0"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full"
}
No mitigation information available for this CWE.
No CAPEC attack patterns related to this CWE.