All 5 CVE vulnerabilities found in opentelemetry-collector-contrib, with AI-generated Chinese analysis, references, and POCs.
Vendor: open-telemetry
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55701 | OpenTelemetry githubreceiver silently ignores configured required_headers authentication CWE-863 | 6.9 | Medium | 2026-09-15 |
| CVE-2026-47256 | OpenTelemetry: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token CWE-22 | 5.3 | Medium | 2026-09-14 |
| CVE-2026-42602 | azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay CWE-208 | 8.1 | High | 2026-05-13 |
| CVE-2024-45043 | OpenTelemetry Collector AWS Firehose Receiver Authentication Bypass Vulnerability CWE-200 | 5.3 | Medium | 2024-08-28 |
| CVE-2024-42368 | open-telemetry has an Observable Timing Discrepancy CWE-208 | 6.5 | Medium | 2024-08-13 |
All 5 known CVE vulnerabilities affecting opentelemetry-collector-contrib with full Chinese analysis, references, and POCs where available.