Skip to content

Exporters reading response body have no size limit #2079

@kaylareopelle

Description

@kaylareopelle

Our OTLP exporters read the full HTTP response body into memory without a size cap.

Limiting the read size may help prevent memory exhaustion exploits when the configured collector endpoint is attacker-controlled (or a network attacker can mitm the exporter connection).

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingstale

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions