Opentelemetry

Opentelemetry

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.01%
  • Veröffentlicht 08.04.2026 20:26:41
  • Zuletzt bearbeitet 10.04.2026 21:16:27

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking a...

  • EPSS 0.02%
  • Veröffentlicht 08.04.2026 20:24:19
  • Zuletzt bearbeitet 09.04.2026 18:39:55

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion w...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 07.04.2026 20:29:13
  • Zuletzt bearbeitet 14.04.2026 18:45:01

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and al...

  • EPSS 4.3%
  • Veröffentlicht 10.11.2023 19:15:16
  • Zuletzt bearbeitet 28.10.2025 19:15:40

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` ...

  • EPSS 1.16%
  • Veröffentlicht 12.10.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 08:26:25

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent` and `http.method` that have unbound cardinality. It leads to the server's potential memory exhaustio...

  • EPSS 0.32%
  • Veröffentlicht 06.10.2023 14:15:12
  • Zuletzt bearbeitet 21.11.2024 08:24:49

OpenTelemetry, also known as OTel for short, is a vendor-neutral open-source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, logs. Autoinstrumentation out of the box adds the la...