Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-995v-fvrw-c78m | opentelemetry-go's Schema ParseFile leaks file descriptors on each parse |
Sat, 13 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 08 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opentelemetry
Opentelemetry opentelemetry-go |
|
| Vendors & Products |
Opentelemetry
Opentelemetry opentelemetry-go |
Thu, 04 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1.0` and `go.opentelemetry.io/otel/schema/v1.1` leaks one file descriptor on each successful `ParseFile` call. `ParseFile` opens the schema file and passes it to `Parse` without closing it; repeated parsing in a long-running process can exhaust the process file descriptor limit and cause denial of service. Exploitation depends on a consuming application exposing repeated schema parsing to an attacker-controlled path. Version 0.0.17 contains a patch for the issue. | |
| Title | OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse | |
| Weaknesses | CWE-772 CWE-775 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-08T18:27:46.212Z
Reserved: 2026-05-11T20:14:43.200Z
Link: CVE-2026-45287
Updated: 2026-06-08T18:27:42.302Z
Status : Awaiting Analysis
Published: 2026-06-04T16:16:38.690
Modified: 2026-06-08T19:16:45.260
Link: CVE-2026-45287
OpenCVE Enrichment
Updated: 2026-06-05T10:07:37Z
Github GHSA