open-telemetry opentelemetry-go

8 known vulnerabilities in open-telemetry opentelemetry-go, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-81872 CVSS 6.3 medium OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log…
  • CVE-2026-81871 CVSS 6.3 medium OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads…
  • CVE-2026-81869 CVSS 5.1 medium OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation…
  • CVE-2026-81870 CVSS 2.0 low OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a…
  • CVE-2026-39883 CVSS 7.3 high OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg…
  • CVE-2026-39882 CVSS 5.3 medium OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full…
  • CVE-2026-29181 CVSS 7.5 high OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each…
  • CVE-2026-24051 CVSS 7.0 high OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path…