{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/opentelemetry-collector--124.0.6367.155/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:opentelemetry-collector:*:*:*:*:*:*:*:*","cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*","cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.6,"id":"CVE-2024-4558"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["opentelemetry-collector (\u003c 124.0.6367.155)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","denial-of-service"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA vulnerability has been identified in the opentelemetry-collector package provided within Red Hat Enterprise Linux distributions. The issue, tracked as CVE-2024-4558, allows a remote, unauthenticated attacker to cause a denial of service condition. This impact is significant for environments relying on the collector for observability and infrastructure monitoring, as successful exploitation results in the cessation of data processing and reporting. Defenders should prioritize updating the opentelemetry-collector package to the patched version provided by Red Hat to restore the stability of telemetry pipelines.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this vulnerability results in a denial of service, rendering the opentelemetry-collector unresponsive. This causes a loss of observability data for systems monitored by the collector, potentially impacting the ability of security operations centers to ingest telemetry, logs, or metrics essential for incident detection and system performance monitoring.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching the affected infrastructure by applying the latest security updates released by Red Hat for the opentelemetry-collector package. Verify system stability post-patching to ensure that service interruptions related to CVE-2024-4558 are resolved.\u003c/p\u003e\n","date_modified":"2026-09-25T14:01:19Z","date_published":"2026-09-25T14:01:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rhel-otel-dos/","summary":"A vulnerability in the opentelemetry-collector package within Red Hat Enterprise Linux allows a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting monitoring and telemetry data collection services.","title":"Denial of Service Vulnerability in Red Hat Enterprise Linux opentelemetry-collector","url":"https://feed.craftedsignal.io/briefs/2026-09-rhel-otel-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Opentelemetry-Collector (\u003c 124.0.6367.155)","version":"https://jsonfeed.org/version/1.1"}