Vulnerabilities in open-telemetry
58 resultsVexday analysis
Open Telemetry apresenta volume moderado de vulnerabilidades (48 CVEs), com agravante de 28 lançadas nos últimos 90 dias, indicando ritmo acelerado de descobertas recentes. Nenhuma está sob exploração ativa (KEV zero) e apenas uma crítica foi registrada, reduzindo a urgência imediata. A fraqueza dominante é CWE-770 (alocação excessiva de recursos), padrão em componentes de processamento de dados que demanda atenção em ambientes de alta carga.
CVE-2024-32028MEDIUMSensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCoreEPSS 0.3%CVE-2026-40891MEDIUMOpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handlingEPSS 0.3%CVE-2026-44213MEDIUMOpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configuredEPSS 0.2%CVE-2026-39882MEDIUMOpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodiesEPSS 0.2%CVE-2026-41433HIGHOpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIREPSS 0.2%CVE-2026-39883HIGHOpenTelemetry-Go has an incomplete fix for CVE-2026-24051: BSD kenv command not using absolute path enables PATH hijackingEPSS 0.2%CVE-2026-81870LOWOpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logsEPSS 0.2%CVE-2026-48496MEDIUMopentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agentEPSS 0.2%CVE-2026-81869MEDIUMOpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncationEPSS 0.2%CVE-2026-45684MEDIUMOpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffersEPSS 0.2%CVE-2026-81192HIGHOpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOSEPSS 0.2%CVE-2026-45683LOWOpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosureEPSS 0.2%CVE-2026-45287LOWOpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parseEPSS 0.2%CVE-2026-24051HIGHOpenTelemetry-Go Affected by Arbitrary Code Execution via PATH HijackingEPSS 0.2%CVE-2026-45676MEDIUMOpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agentEPSS 0.2%CVE-2026-45682MEDIUMOpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removalsEPSS 0.2%CVE-2026-42191MEDIUMOpenTelemetry.Exporter.OpenTelemetryProtocol: Disk retry default temp path enables local blob injection for OTLP ExporterEPSS 0.1%CVE-2026-45404MEDIUMOpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent accessEPSS 0.1%