{"schema_version":1,"title":"OpenTelemetry Go SDK vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 5 vulnerabilities in OpenTelemetry Go SDK: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-39883, was published on 8 April 2026.","url":"https://junglewise.ai/threats/technologies/go-sdk","json_url":"https://junglewise.ai/threats/technologies/go-sdk.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/go-sdk","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":5,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":5},"latest":[{"cve":"CVE-2026-39883","cvss":7,"epss":0.0021,"slug":"cve-2026-39883-opentelemetry-opentelemetry-go-untrusted-search-path-in-host-id","title":"OpenTelemetry OpenTelemetry-Go untrusted search path in host ID detection","severity":"high","exploited":false,"published_at":"2026-04-08T21:17:00.697+00:00","url":"https://junglewise.ai/threats/cve-2026-39883-opentelemetry-opentelemetry-go-untrusted-search-path-in-host-id"},{"cve":"CVE-2026-29181","cvss":7.5,"epss":0.0087,"slug":"cve-2026-29181-opentelemetry-opentelemetry-go-resource-exhaustion-in-baggage","title":"OpenTelemetry OpenTelemetry-Go resource exhaustion in baggage header extraction","severity":"high","exploited":false,"published_at":"2026-04-07T21:17:16.003+00:00","url":"https://junglewise.ai/threats/cve-2026-29181-opentelemetry-opentelemetry-go-resource-exhaustion-in-baggage"},{"cve":"CVE-2026-34742","cvss":8.1,"epss":0.0066,"slug":"cve-2026-34742-modelcontextprotocol-go-sdk-dns-rebinding-in-http-handlers","title":"modelcontextprotocol go-sdk DNS rebinding in HTTP handlers","severity":"high","exploited":false,"published_at":"2026-04-02T19:21:33.023+00:00","url":"https://junglewise.ai/threats/cve-2026-34742-modelcontextprotocol-go-sdk-dns-rebinding-in-http-handlers"},{"cve":"CVE-2026-27896","cvss":7.5,"epss":0.0046,"slug":"cve-2026-27896-model-context-protocol-go-sdk-improper-case-sensitivity-in-json","title":"Model Context Protocol Go SDK improper case sensitivity in JSON-RPC parsing","severity":"high","exploited":false,"published_at":"2026-02-26T01:16:25.63+00:00","url":"https://junglewise.ai/threats/cve-2026-27896-model-context-protocol-go-sdk-improper-case-sensitivity-in-json"},{"cve":"CVE-2026-24051","cvss":7,"epss":0.0017,"slug":"cve-2026-24051-opentelemetry-go-sdk-path-hijacking-in-host-id-go-on-macos","title":"OpenTelemetry Go SDK path hijacking in host_id.go on macOS","severity":"high","exploited":false,"published_at":"2026-02-02T23:16:07.963+00:00","url":"https://junglewise.ai/threats/cve-2026-24051-opentelemetry-go-sdk-path-hijacking-in-host-id-go-on-macos"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Opentelemetry-Ebpf-Instrumentation","slug":"ebpf-instrumentation","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/ebpf-instrumentation"},{"name":"Opentelemetry Otelhttp","slug":"otelhttp","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/otelhttp"},{"name":"Opentelemetry-Go","slug":"opentelemetry-go","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/opentelemetry-go"},{"name":"Opentelemetry","slug":"opentelemetry","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/opentelemetry"},{"name":"Opentelemetry Java Instrumentation","slug":"java-instrumentation","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/java-instrumentation"}],"technology":{"hub":true,"name":"OpenTelemetry Go SDK","slug":"go-sdk","vendor":{"name":"Opentelemetry","slug":"opentelemetry","url":"https://junglewise.ai/threats/vendors/opentelemetry"},"aliases":[],"category":"library","homepage":"https://opentelemetry.io/docs/languages/go/","repo_url":"https://github.com/open-telemetry/opentelemetry-go","description":"The Go implementation of the OpenTelemetry observability framework.","url":"https://junglewise.ai/threats/technologies/go-sdk"},"most_severe":[{"cve":"CVE-2026-34742","cvss":8.1,"epss":0.0066,"slug":"cve-2026-34742-modelcontextprotocol-go-sdk-dns-rebinding-in-http-handlers","title":"modelcontextprotocol go-sdk DNS rebinding in HTTP handlers","severity":"high","exploited":false,"published_at":"2026-04-02T19:21:33.023+00:00","url":"https://junglewise.ai/threats/cve-2026-34742-modelcontextprotocol-go-sdk-dns-rebinding-in-http-handlers"},{"cve":"CVE-2026-29181","cvss":7.5,"epss":0.0087,"slug":"cve-2026-29181-opentelemetry-opentelemetry-go-resource-exhaustion-in-baggage","title":"OpenTelemetry OpenTelemetry-Go resource exhaustion in baggage header extraction","severity":"high","exploited":false,"published_at":"2026-04-07T21:17:16.003+00:00","url":"https://junglewise.ai/threats/cve-2026-29181-opentelemetry-opentelemetry-go-resource-exhaustion-in-baggage"},{"cve":"CVE-2026-27896","cvss":7.5,"epss":0.0046,"slug":"cve-2026-27896-model-context-protocol-go-sdk-improper-case-sensitivity-in-json","title":"Model Context Protocol Go SDK improper case sensitivity in JSON-RPC parsing","severity":"high","exploited":false,"published_at":"2026-02-26T01:16:25.63+00:00","url":"https://junglewise.ai/threats/cve-2026-27896-model-context-protocol-go-sdk-improper-case-sensitivity-in-json"},{"cve":"CVE-2026-39883","cvss":7,"epss":0.0021,"slug":"cve-2026-39883-opentelemetry-opentelemetry-go-untrusted-search-path-in-host-id","title":"OpenTelemetry OpenTelemetry-Go untrusted search path in host ID detection","severity":"high","exploited":false,"published_at":"2026-04-08T21:17:00.697+00:00","url":"https://junglewise.ai/threats/cve-2026-39883-opentelemetry-opentelemetry-go-untrusted-search-path-in-host-id"},{"cve":"CVE-2026-24051","cvss":7,"epss":0.0017,"slug":"cve-2026-24051-opentelemetry-go-sdk-path-hijacking-in-host-id-go-on-macos","title":"OpenTelemetry Go SDK path hijacking in host_id.go on macOS","severity":"high","exploited":false,"published_at":"2026-02-02T23:16:07.963+00:00","url":"https://junglewise.ai/threats/cve-2026-24051-opentelemetry-go-sdk-path-hijacking-in-host-id-go-on-macos"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}