Opentelemetry

Opentelemetry

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 12.06.2026 14:52:00
  • Zuletzt bearbeitet 16.06.2026 19:38:23

OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This is exploitable for memory exha...

  • EPSS 0.3%
  • Veröffentlicht 23.04.2026 18:16:28
  • Zuletzt bearbeitet 29.04.2026 13:52:26

OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry to a back-end/collector over gRPC or HTTP using OpenTelemetry Protocol format (OTLP), if the request results in a unsuccessful request (i.e. ...

  • EPSS 0.19%
  • Veröffentlicht 23.04.2026 18:16:28
  • Zuletzt bearbeitet 29.04.2026 14:15:05

OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC using the OpenTelemetry Protocol (OTLP), the exporter may parse a server-provided grpc-status-details-bin trailer during retry hand...

  • EPSS 0.22%
  • Veröffentlicht 23.04.2026 18:05:41
  • Zuletzt bearbeitet 28.04.2026 19:24:14

OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow sustained memory pressure when the internal pooled-list sizing grows based on a large observed span/tag set and that enlarged siz...

  • EPSS 0.46%
  • Veröffentlicht 23.04.2026 18:03:28
  • Zuletzt bearbeitet 28.04.2026 19:34:26

OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry....

Exploit
  • EPSS 0.2%
  • Veröffentlicht 08.04.2026 20:26:41
  • Zuletzt bearbeitet 10.04.2026 21:16:27

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking a...

  • EPSS 0.19%
  • Veröffentlicht 08.04.2026 20:24:19
  • Zuletzt bearbeitet 09.04.2026 18:39:55

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion w...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 07.04.2026 20:29:13
  • Zuletzt bearbeitet 14.04.2026 18:45:01

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and al...

  • EPSS 0.16%
  • Veröffentlicht 02.02.2026 23:16:07
  • Zuletzt bearbeitet 15.06.2026 17:18:58

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go ex...

  • EPSS 1.58%
  • Veröffentlicht 10.11.2023 19:15:16
  • Zuletzt bearbeitet 28.10.2025 19:15:40

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` ...