Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

open-telemetry — Vulnerabilities & Security Advisories 58

Browse all 58 CVE security advisories affecting open-telemetry. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenTelemetry serves as a vendor-agnostic framework for generating, collecting, and exporting telemetry data, primarily supporting observability in cloud-native environments. Despite its utility in monitoring system performance, the project has recorded twenty-one Common Vulnerabilities and Exposures (CVEs), reflecting inherent risks in complex distributed systems. Historically, these security issues have predominantly stemmed from improper input validation, leading to remote code execution and cross-site scripting vulnerabilities, alongside occasional privilege escalation flaws arising from insufficient access controls. While no single catastrophic incident has defined the project’s history, the accumulation of these defects highlights the challenges of maintaining security in open-source infrastructure tools. Developers must rigorously audit dependencies and enforce strict input sanitization to mitigate these persistent threats, ensuring that the widespread adoption of telemetry does not inadvertently expand the attack surface for critical enterprise applications.

CVE ID Title CVSS Severity Published
CVE-2026-81871 OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning — opentelemetry-go CWE-295 6.3 Medium 2026-09-16
CVE-2026-81872 OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full — opentelemetry-go CWE-400 6.3 Medium 2026-09-16
CVE-2026-81869 OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation — opentelemetry-go CWE-176 5.1 Medium 2026-09-16
CVE-2026-81870 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs — opentelemetry-go CWE-200 2.0 Low 2026-09-16
CVE-2026-55701 OpenTelemetry githubreceiver silently ignores configured required_headers authentication — opentelemetry-collector-contrib CWE-863 6.9 Medium 2026-09-15
CVE-2026-47256 OpenTelemetry: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token — opentelemetry-collector-contrib CWE-22 5.3 Medium 2026-09-14
CVE-2026-47701 OpenTelemetry Operator: ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth — opentelemetry-operator CWE-200 7.7 High 2026-09-14
CVE-2026-48496 opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent — opentelemetry-ebpf-profiler CWE-770 6.2 Medium 2026-09-11
CVE-2026-81192 OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS — opentelemetry-dotnet-contrib CWE-426 7.0 High 2026-09-08
CVE-2026-45404 OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access — opentelemetry-go CWE-362 5.9 Medium 2026-08-24
CVE-2026-48504 OpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagation — opentelemetry-rust CWE-770 5.3 Medium 2026-07-17
CVE-2026-59892 OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header — opentelemetry-js CWE-248 7.5 High 2026-07-08
CVE-2026-54712 OpenTelemetry Javaagent RMI context propagation allows resource exhaustion — opentelemetry-java-instrumentation CWE-400 5.3 Medium 2026-07-01
CVE-2026-54704 OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords — opentelemetry-java-instrumentation CWE-532 6.5 Medium 2026-07-01
CVE-2026-54285 opentelemetry-js: Unbounded memory allocation in W3C Baggage propagation — opentelemetry-js CWE-770 5.3 Medium 2026-06-22
CVE-2026-44967 opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response — opentelemetry-cpp CWE-789 5.3 Medium 2026-06-12
CVE-2026-45287 OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse — go.opentelemetry.io/otel/schema/v1.1 CWE-772 - - 2026-06-04
CVE-2026-41178 OpenTelemetry-Go's baggage parsing no longer caps raw header length — go.opentelemetry.io/otel/baggage CWE-789 5.3 Medium 2026-06-04
CVE-2026-45686 OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI — opentelemetry-ebpf-instrumentation CWE-190 7.5 High 2026-06-02
CVE-2026-45685 OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages — opentelemetry-ebpf-instrumentation CWE-20 7.5 High 2026-06-02
CVE-2026-45684 OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers — opentelemetry-ebpf-instrumentation CWE-126 4.9 Medium 2026-06-02
CVE-2026-45683 OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure — opentelemetry-ebpf-instrumentation CWE-127 3.8 Low 2026-06-02
CVE-2026-45681 OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size — opentelemetry-ebpf-instrumentation CWE-125 5.9 Medium 2026-06-02
CVE-2026-45680 OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU — opentelemetry-ebpf-instrumentation CWE-400 5.9 Medium 2026-06-02
CVE-2026-45679 OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages — opentelemetry-ebpf-instrumentation CWE-117 6.5 Medium 2026-06-02
CVE-2026-45678 OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads — opentelemetry-ebpf-instrumentation CWE-20 7.5 High 2026-06-02
CVE-2026-45676 OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent — opentelemetry-ebpf-instrumentation CWE-20 5.5 Medium 2026-06-02
CVE-2026-45682 OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals — opentelemetry-ebpf-instrumentation CWE-401 5.1 Medium 2026-06-02
CVE-2026-45292 opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation — opentelemetry-java CWE-770 5.3 Medium 2026-05-28
CVE-2026-44902 opentelemetry-js: Prometheus exporter process crash via malformed HTTP request — opentelemetry-js CWE-755 7.5 High 2026-05-27

This page lists every published CVE security advisory associated with open-telemetry. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.