Vendor
Opentelemetry vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 42 vulnerabilities in Opentelemetry: 0 in the last 7 days and 12 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-81872, was published on 16 September 2026. 6 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 12
- Critical, all time
- 1
- Exploited in the wild
- 0
About Opentelemetry
Open standard for observability that defines APIs and SDKs for distributed tracing, metrics, and logging.
Opentelemetry technologies
Latest Opentelemetry vulnerabilities
- CVE-2026-81872: OpenTelemetry-Go BatchingProcessor CPU exhaustion via log emissioninfoEPSS 0.5%
- CVE-2026-81871: OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the…mediumCVSS 5.9EPSS 0.3%
- CVE-2026-81869: OpenTelemetry-Go attribute truncation bypass with Unicode replacement characterinfoEPSS 0.2%
- CVE-2026-81870: OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider…lowCVSS 0EPSS 0.2%
- CVE-2026-55701: The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the…mediumCVSS 6.9EPSS 0.7%
- CVE-2026-47256: OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating…mediumCVSS 5.3EPSS 0.4%
- CVE-2026-47701: The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator…highCVSS 7.7EPSS 0.5%
- CVE-2026-48496: OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages…mediumCVSS 6.2EPSS 0.2%
- CVE-2026-45404: OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's…mediumCVSS 5.9EPSS 0.1%
- CVE-2026-59892: OpenTelemetry opentelemetry-js denial of service in JaegerPropagatorhighCVSS 7.5EPSS 0.8%
- CVE-2026-54712: OpenTelemetry Java Instrumentation DoS in RMI context propagationmediumCVSS 5.3EPSS 0.3%
- CVE-2026-54704: OpenTelemetry Java Instrumentation information disclosure in JDBC auto-instrumentationmediumCVSS 6.5EPSS 0.2%
- CVE-2026-54285: OpenTelemetry opentelemetry-js unbounded memory allocation in W3C BaggagemediumCVSS 5.3EPSS 0.4%
- CVE-2026-44967: OpenTelemetry-cpp memory exhaustion in OTLP HTTP exportersmediumCVSS 5.3EPSS 0.0%
- CVE-2026-45287: OpenTelemetry-Go file descriptor leak in schema ParseFilelowCVSS 2.1
- CVE-2026-41178: OpenTelemetry-Go Denial of Service via oversized baggage headersmediumCVSS 5.3
- CVE-2026-45686: OpenTelemetry eBPF Instrumentation integer overflow in Memcached parserhighCVSS 7.5
- CVE-2026-45685: OpenTelemetry eBPF Instrumentation denial of service in MongoDB parserhighCVSS 7.5
- CVE-2026-45684: OpenTelemetry eBPF Instrumentation buffer over-read in log enrichermediumCVSS 4.9
- CVE-2026-45683: OpenTelemetry OBI kernel memory disclosure in Java TLS ioctl probelowCVSS 3.8
- CVE-2026-45682: OpenTelemetry eBPF Instrumentation memory leak in Java TLS trackingmediumCVSS 5.1
- CVE-2026-45681: OpenTelemetry eBPF Instrumentation out-of-bounds read in message-buffer fallbackmediumCVSS 5.9
- CVE-2026-45680: OpenTelemetry eBPF Instrumentation CPU exhaustion via excessive iterationmediumCVSS 5.9
- CVE-2026-45679: OpenTelemetry eBPF Instrumentation information disclosure in Redis spansmediumCVSS 6.5
- CVE-2026-45678: OpenTelemetry OBI denial of service in Postgres protocol parserhighCVSS 7.5
Most severe Opentelemetry vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33701: OpenTelemetry Java Instrumentation RCE via Unsafe Deserialization in RMIcriticalCVSS 9.8EPSS 0.9%
- CVE-2026-41433: OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted…highCVSS 8.4
- CVE-2026-42602: OpenTelemetry azureauthextension authentication bypass via token replayhighCVSS 8.1EPSS 0.0%
- CVE-2026-47701: The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator…highCVSS 7.7EPSS 0.5%
- CVE-2026-59892: OpenTelemetry opentelemetry-js denial of service in JaegerPropagatorhighCVSS 7.5EPSS 0.8%
- CVE-2026-44902: OpenTelemetry opentelemetry-js denial of service in Prometheus exporterhighCVSS 7.5EPSS 0.5%
- CVE-2026-29181: OpenTelemetry OpenTelemetry-Go resource exhaustion in baggage header extractionhighCVSS 7.5EPSS 0.3%
- CVE-2026-45686: OpenTelemetry eBPF Instrumentation integer overflow in Memcached parserhighCVSS 7.5
- CVE-2026-45685: OpenTelemetry eBPF Instrumentation denial of service in MongoDB parserhighCVSS 7.5
- CVE-2026-45678: OpenTelemetry OBI denial of service in Postgres protocol parserhighCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 7 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/opentelemetry.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Opentelemetry vulnerabilities", https://junglewise.ai/threats/vendors/opentelemetry, 26 September 2026.