Executive brief
OpenTelemetry-Go is a library used for instrumenting applications to collect performance and diagnostic data. A flaw in the library's schema parsing component causes it to leak system resources (file descriptors) every time a schema file is processed. If an application using this library repeatedly parses files—especially if triggered by external input—it can eventually crash or become unresponsive, leading to a denial of service.
Technical details
A resource leak exists in the `ParseFile` function within the `go.opentelemetry.io/otel/schema` package (v1.0 and v1.1). The function opens a schema file using `os.Open` but fails to close the resulting file descriptor after passing it to the `Parse` function. Because the `Parse` function accepts an `io.Reader` and does not take ownership of the closing logic, the descriptor remains open until the Go runtime eventually finalizes the object. In long-running processes or those that expose schema parsing to attacker-controlled paths, this leads to file descriptor exhaustion (EMFILE), causing a denial of service. The issue is resolved in version 0.0.17.
Affected products
- OpenTelemetry go.opentelemetry.io/otel/schema/v1.0 <= v0.0.16
- OpenTelemetry go.opentelemetry.io/otel/schema/v1.1 <= v0.0.16
Timeline
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-06-04: disclosed: CVE-2026-45287 published to NVD