CVE-2023-43810 is a denial-of-service vulnerability affecting OpenTelemetry (OTel) versions prior to 0.41b0. It arises from the autoinstrumentation of HTTP handlers, which adds an 'http_method' label with unbound cardinality, allowing an attacker to send numerous malicious requests with random, long HTTP methods. This can lead to server memory exhaustion. The vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity, requiring no privileges or user interaction, and resulting in high availability impact. The EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.41b0CPE matchmatch criteria | cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.