NONE · 0

CVE-2026-55701

The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders...

Vulnerability Description

The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiver/githubreceiver/trace_receiver.go handleReq() does not check those headers on incoming webhook requests. An unauthenticated sender can therefore bypass an operator's required_headers authentication control and submit arbitrary webhook payloads. When the Secret field is empty, github.ValidatePayload also skips HMAC validation, leaving the webhook endpoint without either configured authentication mechanism. Successful exploitation can inject fabricated CI/CD trace data into the observability pipeline. This issue is fixed in version 0.151.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-55701?

CVE-2026-55701 is a documented vulnerability. The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders...

How severe is CVE-2026-55701?

CVSS scoring is not yet available for CVE-2026-55701. Check NVD for updates.

Is there a patch for CVE-2026-55701?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.