Dev Reveals Sanitizer Bypass Bug Leaking Sensitive Data for 13 Releases
The author of opentel-mcp disclosed a privacy leak that persisted across 13 releases: a line following the sanitization call in OpenTelemetry's recordException bypassed the fingerprint masking, sending emails, IPs, and URLs unsanitized.
2026-08-31 ~ 2026-08-31 · 2 related posts
- My own scrubber was bypassed by the very next line — leak survived 13 releases — Thirumalaiboobathi · 2026-08-31
- Dev Shares Critical Privacy Leak in Scrubber: Raw Data Emitted After Sanitization — selfhostcusimbored · 2026-08-31