CVE-2026-45287: OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse

Published May 28, 2026
·
Updated

Summary

go.opentelemetry.io/otel/schema/v1.0 and go.opentelemetry.io/otel/schema/v1.1 leaks one file descriptor on each successful ParseFile call. ParseFile opens the schema file and passes it to Parse without closing it; repeated parsing in a long-running process can exhaust the process file descriptor limit and cause denial of service. The severity is low because exploitation depends on a consuming application exposing repeated schema parsing to an attacker-controlled path.

Introduced in commit: e72a235

Details

In schema/v1.0/parser.go:41-47, ParseFile opens the requested schema path with os.Open and then returns Parse(file) without a defer file.Close() or other close path:

go file, err := os.Open(schemaFilePath) if err != nil { return nil, err } return Parse(file)

The validation evidence also identifies schema/v1.0/parser.go:50-73: Parse accepts an io.Reader, decodes from it, and does not close it. Ownership of the opened file is therefore not transferred to Parse, leaving the descriptor open until the Go runtime eventually finalizes the file object. With repeated ParseFile calls, descriptors can accumulate until the process receives EMFILE / "too many open files".

PoC

validation-artifact.zip

The local artifact validation-artifact.zip contains:

- leakpoc.go: PoC source that repeatedly calls schema.ParseFile("schema/v1.0/testdata/valid-example.yaml") and prints /proc/self/fd counts. - LEAKPOCREADME.txt: reproduction notes. - leakpocrun.log: captured attempted run; the local offline environment failed before execution because Go module download from proxy.golang.org was forbidden.

Reproduce from the root of a checkout of pellared/opentelemetry-go at commit e72a235 with Go module dependencies already available:

sh /bin/sh -c 'ulimit -n 256; GOGC=off go run leakpoc.go'

Configuration:

- File descriptor soft limit: 256 - Garbage collection: disabled with GOGC=off so leaked descriptors are not reclaimed during the loop - Schema file: schema/v1.0/testdata/valid-example.yaml

Expected output is increasing descriptor counts followed by an EMFILE failure, for example:

text iter 0 fds 7 iter 50 fds 57 iter 100 fds 107 ... panic: iteration 248: open schema/v1.0/testdata/valid-example.yaml: too many open files

The exact initial descriptor count and failing iteration can vary by OS and process state.

Impact

This is a file descriptor resource leak leading to availability loss. Applications that call schema.ParseFile repeatedly, especially through a runtime reload or request-controlled path, can exhaust their process file descriptor table and fail subsequent file, socket, or other descriptor operations. Impact is limited to denial of service of the consuming process; the evidence does not show confidentiality or integrity impact.

Other sources

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, go.opentelemetry.io/otel/schema/v1.0 and go.opentelemetry.io/otel/schema/v1.1 leaks one file descriptor on each successful ParseFile call. ParseFile opens the schema file and passes it to Parse without closing it; repeated parsing in a long-running process can exhaust the process file descriptor limit and cause denial of service. Exploitation depends on a consuming application exposing repeated schema parsing to an attacker-controlled path. Version 0.0.17 contains a patch for the issue.

MITRE

Affected Software

3 affected componentsFixes available
go/go.opentelemetry.io/otel/schema/v1.0<=0.0.16
0.0.17
go/go.opentelemetry.io/otel/schema/v1.1<=0.0.16
0.0.17
OpenTelemetry Telemetry Schema Files Go<0.0.17

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/go.opentelemetry.io/otel/schema/v1.0 to a version that resolves this vulnerability.

    Fixed in 0.0.17
  2. Upgrade

    Upgrade go/go.opentelemetry.io/otel/schema/v1.1 to a version that resolves this vulnerability.

    Fixed in 0.0.17
  3. Upgrade

    Upgrade go.opentelemetry.io/otel/schema/v1.0 to a version that resolves this vulnerability.

    Fixed in 0.0.17
  4. Upgrade

    Upgrade go.opentelemetry.io/otel/schema/v1.1 to a version that resolves this vulnerability.

    Fixed in 0.0.17
  5. Configuration

    Do not use `GOGC=off` in production; enable garbage collection so leaked file objects are less likely to persist (the PoC disables GC with `GOGC=off` so leaked descriptors are not reclaimed during the loop).

    Go runtime (PoC setting) GOGC = off
  6. Compensating control

    Set a process file descriptor soft limit low enough to prevent uncontrolled exhaustion (e.g., the PoC uses `ulimit -n 256` before running with `GOGC=off`).

Event History

May 28, 2026
Advisory Published
via GitHub·05:19 PM
Data Sourced
via GitHub·05:19 PM
DescriptionWeaknessAffected Software
Jun 4, 2026
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-45287?

CVE-2026-45287 has a risk rating of 22.

2

How do I fix CVE-2026-45287?

To fix CVE-2026-45287, upgrade to a version of go.opentelemetry.io/otel/schema that addresses the file descriptor leak.

3

What is the impact of CVE-2026-45287?

CVE-2026-45287 can lead to file descriptor exhaustion in long-running processes due to unreleased file descriptors.

4

Which versions of OpenTelemetry are affected by CVE-2026-45287?

CVE-2026-45287 affects both go.opentelemetry.io/otel/schema/v1.0 and go.opentelemetry.io/otel/schema/v1.1.

5

Is CVE-2026-45287 a critical vulnerability?

Yes, CVE-2026-45287 can cause significant issues in production environments if not addressed due to resource exhaustion.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2026-45287 - OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse - SecAlerts