The vulnerability lies in the lack of input validation in the baggage propagation implementations within OpenTelemetry Java SDK. Specifically, the W3CBaggagePropagator, JaegerPropagator, and OtTracePropagator did not enforce any limits on the size or number of entries in the baggage headers they were parsing. This allowed a malicious actor to send a specially crafted, oversized baggage header, which would cause the application to consume an unbounded amount of memory and CPU resources during parsing, leading to a denial of service.
The extract methods of these propagators are the primary entry points for the vulnerability, as they are responsible for reading and parsing the baggage from incoming requests. The inject methods are also part of the vulnerability's impact, as they would propagate the oversized baggage to downstream services, causing the denial of service to cascade through a distributed system.
The fix, as seen in the provided commit, was to introduce and enforce limits on the maximum number of baggage entries and the maximum total byte size of the baggage, in line with the W3C Baggage specification recommendations. These checks were added to the extract and inject paths of all three affected propagators.