StackRadar

CVE-2023-45142

High

Advisory

Published 16 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
152
of 17,781 indexed, latest versions
Container images
156
deployed by those charts
Fix available
5 of 5
affected packages

OpenTelemetry-Go Contrib vulnerable to denial of service in otelhttp due to unbound cardinality metrics

Carried by container images the latest versions of 152 of 17,781 indexed charts deploy, on 156 images.

Affected packageAffected versionsFixed inImages
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttpgolangv0.16.0, v0.20.0, v0.22.0, v0.23.0+15 more0.44.0149
go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptracegolangv0.16.0, v0.28.0, v0.29.0, v0.36.4+2 more0.44.023
go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgingolangv0.36.3, v0.36.4, v0.40.0, v0.42.00.44.08
go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestfulgolangv0.20.0, v0.35.0, v0.36.40.44.05
go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmuxgolangv0.22.0, v0.28.00.44.03
OSV records
GHSA-rcjv-mgp8-qvmr
Also known as
GO-2023-2113

Charts affected

152 by stars
ChartLatestAffected imagesRadar Score
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2023-45142.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@v0.42.0
0.44.0

Open the chart page →

2,022
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2023-45142.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@v0.20.0
0.44.0

Open the chart page →

1,958

Container images carrying it

156 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@v0.20.0
0.44.0
1
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@v0.35.1
0.44.0
1
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@v0.35.1
0.44.0
1
registry.k8s.io/kube-scheduler:v1.28.1146cf7475c8da
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@v0.35.1
0.44.0
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@v0.20.0
0.44.0
1
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@v0.35.1
0.44.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.