Vulnerabilities in open-telemetry
58 resultsVexday analysis
Open Telemetry apresenta volume moderado de vulnerabilidades (48 CVEs), com agravante de 28 lançadas nos últimos 90 dias, indicando ritmo acelerado de descobertas recentes. Nenhuma está sob exploração ativa (KEV zero) e apenas uma crítica foi registrada, reduzindo a urgência imediata. A fraqueza dominante é CWE-770 (alocação excessiva de recursos), padrão em componentes de processamento de dados que demanda atenção em ambientes de alta carga.
CVE-2023-47108HIGHDoS vulnerability in otelgrpc (uncontrolled resource consumption) due to unbound cardinality metricsEPSS 1.6%CVE-2023-45142HIGHOpenTelemetry-Go Contrib has DoS vulnerability in otelhttp due to unbound cardinality metricsEPSS 1.4%CVE-2024-36129HIGHOpenTelemetry Collector has a Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPCEPSS 1.2%CVE-2026-45292MEDIUMopentelemetry-java: Unbounded Memory Allocation in W3C Baggage PropagationEPSS 1.1%CVE-2023-25151HIGHDoS vulnerability for high cardinality metrics in opentelemetry-go-contribEPSS 1.0%CVE-2026-33701CRITICALOpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code ExecutionEPSS 0.9%CVE-2023-39951MEDIUMInstrumentation for AWS SDK v2 captures email content when using Amazon Simple Email Service (SES) v1 API, exposing that content to the telemetry backendEPSS 0.8%CVE-2026-29181HIGHOpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)EPSS 0.8%CVE-2026-59892HIGHOpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed headerEPSS 0.8%CVE-2023-43810HIGHopentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metricsEPSS 0.7%CVE-2026-55701MEDIUMOpenTelemetry githubreceiver silently ignores configured required_headers authenticationEPSS 0.7%CVE-2024-42368MEDIUMopen-telemetry has an Observable Timing DiscrepancyEPSS 0.6%CVE-2025-27513HIGHOpenTelemetry .NET has a Denial of Service (DoS) Vulnerability in API PackageEPSS 0.5%CVE-2024-45043MEDIUMOpenTelemetry Collector AWS Firehose Receiver Authentication Bypass VulnerabilityEPSS 0.5%CVE-2026-44902HIGHopentelemetry-js: Prometheus exporter process crash via malformed HTTP requestEPSS 0.5%CVE-2026-45685HIGHOpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messagesEPSS 0.5%CVE-2026-40894MEDIUMOpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headersEPSS 0.5%CVE-2026-48504MEDIUMOpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagationEPSS 0.4%CVE-2026-47256MEDIUMOpenTelemetry: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer tokenEPSS 0.4%CVE-2026-54704MEDIUMOpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text PasswordsEPSS 0.4%