Advisories for Golang/Github.com/Open-Telemetry/Opentelemetry-Collector-Contrib/Receiver/Githubreceiver package

2026

opentelemetry-collector-contrib: githubreceiver silently ignores configured required_headers authentication

The githubreceiver webhook handler does not enforce the required_headers configuration. Headers are validated at startup (config rejects empty keys/values) but never checked on incoming requests. This follows the same pattern as GHSA-prf6-xjxh-p698 (awsfirehosereceiver auth bypass). Verified against current main.