Vulnerabilities in open-telemetry
58 resultsVexday analysis
Open Telemetry apresenta volume moderado de vulnerabilidades (48 CVEs), com agravante de 28 lançadas nos últimos 90 dias, indicando ritmo acelerado de descobertas recentes. Nenhuma está sob exploração ativa (KEV zero) e apenas uma crítica foi registrada, reduzindo a urgência imediata. A fraqueza dominante é CWE-770 (alocação excessiva de recursos), padrão em componentes de processamento de dados que demanda atenção em ambientes de alta carga.
CVE-2026-44902HIGHopentelemetry-js: Prometheus exporter process crash via malformed HTTP requestEPSS 0.5%CVE-2026-45680MEDIUMOpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPUEPSS 0.5%CVE-2026-54712MEDIUMOpenTelemetry Javaagent RMI context propagation allows resource exhaustionEPSS 0.5%CVE-2026-47701HIGHOpenTelemetry Operator: ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer authEPSS 0.5%CVE-2026-47256MEDIUMOpenTelemetry: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer tokenEPSS 0.4%CVE-2026-41484MEDIUMOpenTelemetry.Exporter.OneCollector vulnerable to denial of service via unbounded HTTP error response bodyEPSS 0.4%CVE-2026-48504MEDIUMOpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagationEPSS 0.4%CVE-2026-42348MEDIUMOpAMP client reads unbounded HTTP response bodiesEPSS 0.4%CVE-2026-54285MEDIUMopentelemetry-js: Unbounded memory allocation in W3C Baggage propagationEPSS 0.4%CVE-2026-41310MEDIUMOpenTelemetry .NET Zipkin exporter has unbounded remote endpoint cache leading to memory growthEPSS 0.4%CVE-2026-54704MEDIUMOpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text PasswordsEPSS 0.4%CVE-2026-41173MEDIUMUnbounded HTTP response body read in OpenTelemetry.Sampler.AWSEPSS 0.4%CVE-2026-45681MEDIUMOpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB sizeEPSS 0.4%CVE-2026-41483MEDIUMUnbounded HTTP response body read in OpenTelemetry.Resources.AzureEPSS 0.4%CVE-2026-41078MEDIUMOpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion pathEPSS 0.4%CVE-2026-41178MEDIUMOpenTelemetry-Go's baggage parsing no longer caps raw header lengthEPSS 0.3%CVE-2026-81871MEDIUMOpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinningEPSS 0.3%CVE-2026-42602HIGHazureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replayEPSS 0.3%CVE-2026-45679MEDIUMOpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messagesEPSS 0.3%CVE-2026-44967MEDIUMopentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP responseEPSS 0.3%