Insertion of Sensitive Information into Log File Affecting go.opentelemetry.io/obi/pkg/appolly/app/request package, versions <0.9.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.21% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Insertion of Sensitive Information into Log File vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GOOPENTELEMETRYIOOBIPKGAPPOLLYAPPREQUEST-17670509
  • published7 Jul 2026
  • disclosed18 May 2026
  • creditUnknown

Introduced: 18 May 2026

CVE-2026-45679  (opens in a new tab)
CWE-117  (opens in a new tab)
CWE-532  (opens in a new tab)

How to fix?

Upgrade go.opentelemetry.io/obi/pkg/appolly/app/request to version 0.9.0 or higher.

Overview

Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File in the process that exports Redis error text as span status messages without adequate sanitization. An attacker can cause sensitive information, such as tokens or personally identifiable data, to be exposed in telemetry systems and inject untrusted text into downstream analysis by crafting Redis error replies containing attacker-controlled or confidential values.

CVSS Base Scores

version 4.0
version 3.1