An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-2900" }
{ "imports": [ { "path": "go.opentelemetry.io/collector/config/configgrpc", "symbols": [ "ClientConfig.ToClientConn", "getGRPCCompressionName" ] } ] }
{ "imports": [ { "path": "go.opentelemetry.io/collector/config/confighttp", "symbols": [ "ServerConfig.ToServer", "clientInfoHandler.ServeHTTP", "decompressor.ServeHTTP", "httpContentDecompressor" ] } ] }