Advisories for Golang/Go.opentelemetry.io/Contrib/Instrumentation/Google.golang.org/Grpc/Otelgrpc package

2023

otelgrpc DoS vulnerability due to unbound cardinality metrics

The grpc Unary Server Interceptor opentelemetry-go-contrib/instrumentation/google.golang.org/grpc/otelgrpc/interceptor.go UnaryServerInterceptor returns a grpc.UnaryServerInterceptor suitable for use in a grpc.NewServer call that has unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent.