Intel

AIKIDO-2025-10013

github.com/signalfx/splunk-otel-collector is vulnerable to Race Condition

Race Condition Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

61

Medium Risk

This Affects:

gogithub.com/signalfx/splunk-otel-collector
0.91.3 - 0.115.0
Fixed in 0.116.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by a race condition in a method that implements non-contiguous locks on shared data. This situation allows other goroutines to modify h.sources or h.previousEvents between lock and unlock cycles, which can lead to data corruption and system outages. An attacker could exploit this vulnerability to conduct Denial of Service (DoS) attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/signalfx/splunk-otel-collector is vulnerable to Race Condition in versions 0.91.3 - 0.115.0.

How to fix this

Upgrade the github.com/signalfx/splunk-otel-collector library to the patch version.