Security: open-telemetry/opentelemetry-go
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unsynchronized baggage map can panic under concurrent accessGHSA-42cj-99w8-cp2p published
Aug 20, 2026 by pellaredModerate -
Schema ParseFile leaks file descriptors on each parseGHSA-995v-fvrw-c78m published
May 28, 2026 by pellaredLow -
Exporter config logging may leak endpoint URLs in info logsGHSA-8wmf-6v46-5gfg published
Sep 2, 2026 by pellaredLow -
UTF-8 replacement rune bypasses attribute length truncationGHSA-p9f8-wvj8-2fg8 published
Sep 2, 2026 by pellaredModerate -
BatchProcessor can busy-spin when export buffer is fullGHSA-hjf4-fphr-2h65 published
Sep 2, 2026 by pellaredModerate -
Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinningGHSA-w34q-cm8f-9c5x published
Sep 2, 2026 by pellaredModerate -
Baggage parsing no longer caps raw header lengthGHSA-5wrp-cwcj-q835 published
May 28, 2026 by pellaredModerate -
Incomplete fix for GHSA-9h8m-3fm2-qjrq: BSD kenv command not using absolute path enables PATH hijackingGHSA-hfvc-g4fc-pqhx published
Apr 8, 2026 by dashpoleHigh -
OTLP HTTP exporters read unbounded HTTP response bodiesGHSA-w8rr-5gcm-pp58 published
Apr 8, 2026 by dashpoleModerate -
multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)GHSA-mh2q-q3fh-2475 published
Apr 7, 2026 by dashpoleHigh