OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, expor
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| open-telemetry | opentelemetry-go | >= 1.5.0, < 1.45.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81872 | 6.3 MEDIUM | OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
| CVE-2026-81871 | 6.3 MEDIUM | OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning |
| CVE-2026-81869 | 5.1 MEDIUM | OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation |
No comments yet