mediumVulnerability

CVE-2026-81871

### Summary The OTLP log gRPC exporter loads TLS settings from environment variables but does not apply them when creating gRPC transport credentials. Operators who rely on `OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE`, `OTEL_EXPORTER_OTLP_CERTIFICATE`, or related client certificate variables for CA pinning or mTLS get a connection that falls back to system roots and omits the env-supplied client certificate. A network attacker who can intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. Introduced in commit: d99c76f ### Details The affected code is in `exporters/otlp/otlplog/otlploggrpc`. `newConfig` resolves env-based TLS configuration into `cfg.tlsCfg` at `exporters/otlp/otlplog/otlploggrpc/config.go:106-116`. The finding also identifies `loadEnvTLS` at `config.go:451-492` as the code that builds a `*tls.Config` containing `RootCAs` and client certificates from `OTEL_EXPORTER_OTLP[_LOGS]_CERTIFICATE` and `OTEL_EXPORTER_OTLP[_LOGS]_CLIENT_CERTIFICATE`/`KEY`. However, `newGRPCDialOptions` in `exporters/otlp/otlplog/otlploggrpc/client.go:83-92` only checks `cfg.gRPCCredentials` and `cfg.insecure`. When neither is set, which is the normal env-only TLS configuration path, it uses `credentials.NewTLS(nil)`. That default trusts the host system root CAs and contains no env-supplied client certificate. The finding evidence reports no other `tlsCfg` use in the package, so env-based CA pinning and mTLS settings are loaded but not enforced. ### PoC [validation-artifact.zip](https://github.com/user-attachments/files/27493589/validation-artifact.zip) The validation artifact contains a ready-to-run test at `validation-artifact.zip:./poc_env_tls_ignored_test.go` and brief instructions at `validation-artifact.zip:./README.md`. From a checkout of `pellared/opentelemetry-go` at commit `d99c76f`, with Go module dependencies available: ```sh FINDING_DIR=/path/to/02-e6e2897a969c8191b260f243fbc99ebd-log-grpc-exporter-ignore

Properties

ghsa_id
GHSA-w34q-cm8f-9c5x
severity
medium
summary
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
cve_id
CVE-2026-81871
signal_observed_at
2026-09-17T21:32:39+00:00
is_ghsa_only
false
ghsa_published
2026-09-17T20:31:09Z
source_url
https://github.com/advisories/GHSA-w34q-cm8f-9c5x
ghsa_updated
2026-09-17T20:31:11Z

Related Entities (5)

HAS_WEAKNESS (2)

[Weakness]Improper Certificate Validation
[Weakness]Improper Restriction of Communication Channel to Intended Endpoints

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc

AFFECTS (1)

[Software]go/go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81871 — Ninja Signal Threat Intelligence | Ninja Signal