CVE-2026-41178: opentelemetry-go's baggage parsing no longer caps raw header length
(updated )
https://github.com/open-telemetry/opentelemetry-go/pull/7880 removed raw-length rejection and it causes Parse to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-41178 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →