Bug 2535725 (CVE-2026-81871)

Summary: CVE-2026-81871 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akhatavk, amctagga, anjoseph, anpicker, aoconnor, aos-team-art-private, asdas, bniver, bparees, bsquizza, cahl, cmitchel, crizzo, doconnor, dpaolell, eglynn, elicohen, flucifre, gbenhaim, gmeno, gparvin, groman, gtanzill, hasun, jbalunas, jbuscemi, jcantril, jdelft, jfula, jjoyce, jowilson, jprabhak, jpretori, jschluet, jupierce, lchilton, lgamliel, lgarciaa, lhh, ljawale, mbenjamin, mbiarnes, mburns, mgarciac, mhackett, msilmser, mwringe, niyer, nyancey, ometelka, ppalepu, ppostler, prdhamdh, ptisnovs, rhaigner, rhel-process-autobot, rojacob, sbratsla, sdawley, sfeifer, sghai, sidsharm, sostapov, suppawar, syedriko, teagle, tsze, twaugh, tzivkovi, vereddy, vlaad, watson-tool-maintainers, wtam, xdharmai
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in OpenTelemetry-Go, specifically within its gRPC log exporter. This vulnerability allows a network attacker to bypass the intended private Certificate Authority (CA) pinning and mutual Transport Layer Security (TLS) configurations. The issue arises because the environment-only TLS path incorrectly uses system-trusted certificates instead of the application's configured client certificates. This bypass enables an attacker to intercept and spoof the collector connection, potentially leading to the unauthorized reading or alteration of sensitive log telemetry.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2536929, 2536931, 2536933, 2536934, 2536935, 2536936, 2536938, 2536930, 2536937    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-16 21:13:26 UTC
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS into cfg.tlsCfg, but newGRPCDialOptions does not apply cfg.tlsCfg when creating gRPC transport credentials. The environment-only TLS path instead uses credentials.NewTLS with system roots and no configured client certificate, bypassing intended private CA pinning and mutual TLS unless the application also supplies WithTLSCredentials. A network attacker able to intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. This issue is fixed in version 0.21.0.