{"schema_version":1,"title":"Opentelemetry-Go vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 7 vulnerabilities in Opentelemetry-Go: 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-81872, was published on 16 September 2026.","url":"https://junglewise.ai/threats/technologies/opentelemetry-go","json_url":"https://junglewise.ai/threats/technologies/opentelemetry-go.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/opentelemetry-go","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":7,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":4,"last_90_days":5,"last_365_days":7},"latest":[{"cve":"CVE-2026-81872","epss":0.0052,"slug":"cve-2026-81872-opentelemetry-go-batchingprocessor-cpu-exhaustion-via-log","title":"OpenTelemetry-Go BatchingProcessor CPU exhaustion via log emission","severity":"info","exploited":false,"published_at":"2026-09-16T21:17:22.467+00:00","url":"https://junglewise.ai/threats/cve-2026-81872-opentelemetry-go-batchingprocessor-cpu-exhaustion-via-log"},{"cve":"CVE-2026-81871","cvss":4,"epss":0.0033,"slug":"cve-2026-81871-opentelemetry-go-otlp-log-grpc-exporter-tls-certificate","title":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OT","severity":"medium","exploited":false,"published_at":"2026-09-16T21:17:22.323+00:00","url":"https://junglewise.ai/threats/cve-2026-81871-opentelemetry-go-otlp-log-grpc-exporter-tls-certificate"},{"cve":"CVE-2026-81869","epss":0.0018,"slug":"cve-2026-81869-opentelemetry-go-attribute-truncation-bypass-with-unicode","title":"OpenTelemetry-Go attribute truncation bypass with Unicode replacement character","severity":"info","exploited":false,"published_at":"2026-09-16T21:17:22.18+00:00","url":"https://junglewise.ai/threats/cve-2026-81869-opentelemetry-go-attribute-truncation-bypass-with-unicode"},{"cve":"CVE-2026-81870","cvss":4,"epss":0.002,"slug":"cve-2026-81870-opentelemetry-go-endpoint-url-logging-in-tracerprovider","title":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider","severity":"medium","exploited":false,"published_at":"2026-09-16T20:17:32.733+00:00","url":"https://junglewise.ai/threats/cve-2026-81870-opentelemetry-go-endpoint-url-logging-in-tracerprovider"},{"cve":"CVE-2026-45404","cvss":4,"epss":0.0014,"slug":"cve-2026-45404-opentelemetry-go-unsynchronized-baggage-map-race-condition","title":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains","severity":"medium","exploited":false,"published_at":"2026-08-24T22:16:53.02+00:00","url":"https://junglewise.ai/threats/cve-2026-45404-opentelemetry-go-unsynchronized-baggage-map-race-condition"},{"cve":"CVE-2026-39883","cvss":7,"epss":0.0021,"slug":"cve-2026-39883-opentelemetry-opentelemetry-go-untrusted-search-path-in-host-id","title":"OpenTelemetry OpenTelemetry-Go untrusted search path in host ID detection","severity":"high","exploited":false,"published_at":"2026-04-08T21:17:00.697+00:00","url":"https://junglewise.ai/threats/cve-2026-39883-opentelemetry-opentelemetry-go-untrusted-search-path-in-host-id"},{"cve":"CVE-2026-29181","cvss":7.5,"epss":0.0087,"slug":"cve-2026-29181-opentelemetry-opentelemetry-go-resource-exhaustion-in-baggage","title":"OpenTelemetry OpenTelemetry-Go resource exhaustion in baggage header extraction","severity":"high","exploited":false,"published_at":"2026-04-07T21:17:16.003+00:00","url":"https://junglewise.ai/threats/cve-2026-29181-opentelemetry-opentelemetry-go-resource-exhaustion-in-baggage"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Opentelemetry-Ebpf-Instrumentation","slug":"ebpf-instrumentation","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/ebpf-instrumentation"},{"name":"Opentelemetry Otelhttp","slug":"otelhttp","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/otelhttp"},{"name":"OpenTelemetry Go SDK","slug":"go-sdk","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/go-sdk"},{"name":"Opentelemetry","slug":"opentelemetry","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/opentelemetry"},{"name":"Opentelemetry Java Instrumentation","slug":"java-instrumentation","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/java-instrumentation"}],"technology":{"hub":true,"name":"Opentelemetry-Go","slug":"opentelemetry-go","vendor":{"name":"Opentelemetry","slug":"opentelemetry","url":"https://junglewise.ai/threats/vendors/opentelemetry"},"aliases":[],"category":"library","homepage":"https://opentelemetry.io","repo_url":"https://github.com/open-telemetry/opentelemetry-go","description":"A Go implementation of the OpenTelemetry API and SDK for distributed tracing, metrics, and logs.","url":"https://junglewise.ai/threats/technologies/opentelemetry-go"},"most_severe":[{"cve":"CVE-2026-29181","cvss":7.5,"epss":0.0087,"slug":"cve-2026-29181-opentelemetry-opentelemetry-go-resource-exhaustion-in-baggage","title":"OpenTelemetry OpenTelemetry-Go resource exhaustion in baggage header extraction","severity":"high","exploited":false,"published_at":"2026-04-07T21:17:16.003+00:00","url":"https://junglewise.ai/threats/cve-2026-29181-opentelemetry-opentelemetry-go-resource-exhaustion-in-baggage"},{"cve":"CVE-2026-39883","cvss":7,"epss":0.0021,"slug":"cve-2026-39883-opentelemetry-opentelemetry-go-untrusted-search-path-in-host-id","title":"OpenTelemetry OpenTelemetry-Go untrusted search path in host ID detection","severity":"high","exploited":false,"published_at":"2026-04-08T21:17:00.697+00:00","url":"https://junglewise.ai/threats/cve-2026-39883-opentelemetry-opentelemetry-go-untrusted-search-path-in-host-id"},{"cve":"CVE-2026-81871","cvss":4,"epss":0.0033,"slug":"cve-2026-81871-opentelemetry-go-otlp-log-grpc-exporter-tls-certificate","title":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OT","severity":"medium","exploited":false,"published_at":"2026-09-16T21:17:22.323+00:00","url":"https://junglewise.ai/threats/cve-2026-81871-opentelemetry-go-otlp-log-grpc-exporter-tls-certificate"},{"cve":"CVE-2026-81870","cvss":4,"epss":0.002,"slug":"cve-2026-81870-opentelemetry-go-endpoint-url-logging-in-tracerprovider","title":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider","severity":"medium","exploited":false,"published_at":"2026-09-16T20:17:32.733+00:00","url":"https://junglewise.ai/threats/cve-2026-81870-opentelemetry-go-endpoint-url-logging-in-tracerprovider"},{"cve":"CVE-2026-45404","cvss":4,"epss":0.0014,"slug":"cve-2026-45404-opentelemetry-go-unsynchronized-baggage-map-race-condition","title":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains","severity":"medium","exploited":false,"published_at":"2026-08-24T22:16:53.02+00:00","url":"https://junglewise.ai/threats/cve-2026-45404-opentelemetry-go-unsynchronized-baggage-map-race-condition"},{"cve":"CVE-2026-81872","epss":0.0052,"slug":"cve-2026-81872-opentelemetry-go-batchingprocessor-cpu-exhaustion-via-log","title":"OpenTelemetry-Go BatchingProcessor CPU exhaustion via log emission","severity":"info","exploited":false,"published_at":"2026-09-16T21:17:22.467+00:00","url":"https://junglewise.ai/threats/cve-2026-81872-opentelemetry-go-batchingprocessor-cpu-exhaustion-via-log"},{"cve":"CVE-2026-81869","epss":0.0018,"slug":"cve-2026-81869-opentelemetry-go-attribute-truncation-bypass-with-unicode","title":"OpenTelemetry-Go attribute truncation bypass with Unicode replacement character","severity":"info","exploited":false,"published_at":"2026-09-16T21:17:22.18+00:00","url":"https://junglewise.ai/threats/cve-2026-81869-opentelemetry-go-attribute-truncation-bypass-with-unicode"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}