{"schema_version":1,"title":"Opentelemetry vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 42 vulnerabilities in Opentelemetry: 0 in the last 7 days and 12 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-81872, was published on 16 September 2026. 6 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/opentelemetry","json_url":"https://junglewise.ai/threats/vendors/opentelemetry.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/opentelemetry","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":11,"all_time":42,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":8,"last_90_days":12,"last_365_days":41},"latest":[{"cve":"CVE-2026-81872","epss":0.0052,"slug":"cve-2026-81872-opentelemetry-go-batchingprocessor-cpu-exhaustion-via-log","title":"OpenTelemetry-Go BatchingProcessor CPU exhaustion via log emission","severity":"info","exploited":false,"published_at":"2026-09-16T21:17:22.467+00:00","url":"https://junglewise.ai/threats/cve-2026-81872-opentelemetry-go-batchingprocessor-cpu-exhaustion-via-log"},{"cve":"CVE-2026-81871","cvss":5.9,"epss":0.0033,"slug":"cve-2026-81871-opentelemetry-go-otlp-log-grpc-exporter-tls-certificate","title":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OT","severity":"medium","exploited":false,"published_at":"2026-09-16T21:17:22.323+00:00","url":"https://junglewise.ai/threats/cve-2026-81871-opentelemetry-go-otlp-log-grpc-exporter-tls-certificate"},{"cve":"CVE-2026-81869","epss":0.0018,"slug":"cve-2026-81869-opentelemetry-go-attribute-truncation-bypass-with-unicode","title":"OpenTelemetry-Go attribute truncation bypass with Unicode replacement character","severity":"info","exploited":false,"published_at":"2026-09-16T21:17:22.18+00:00","url":"https://junglewise.ai/threats/cve-2026-81869-opentelemetry-go-attribute-truncation-bypass-with-unicode"},{"cve":"CVE-2026-81870","cvss":0,"epss":0.002,"slug":"cve-2026-81870-opentelemetry-go-endpoint-url-logging-in-tracerprovider","title":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider","severity":"low","exploited":false,"published_at":"2026-09-16T20:17:32.733+00:00","url":"https://junglewise.ai/threats/cve-2026-81870-opentelemetry-go-endpoint-url-logging-in-tracerprovider"},{"cve":"CVE-2026-55701","cvss":6.9,"epss":0.007,"slug":"cve-2026-55701-opentelemetry-collector-githubreceiver-auth-bypass-via-missing","title":"The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver val","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:15.617+00:00","url":"https://junglewise.ai/threats/cve-2026-55701-opentelemetry-collector-githubreceiver-auth-bypass-via-missing"},{"cve":"CVE-2026-47256","cvss":5.3,"epss":0.0044,"slug":"cve-2026-47256-opentelemetry-sentry-exporter-path-traversal-via-service-name","title":"OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and ex","severity":"medium","exploited":false,"published_at":"2026-09-14T18:17:48.25+00:00","url":"https://junglewise.ai/threats/cve-2026-47256-opentelemetry-sentry-exporter-path-traversal-via-service-name"},{"cve":"CVE-2026-47701","cvss":7.7,"epss":0.0046,"slug":"cve-2026-47701-opentelemetry-operator-arbitrary-file-disclosure-in","title":"The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator in","severity":"high","exploited":false,"published_at":"2026-09-14T16:17:11.54+00:00","url":"https://junglewise.ai/threats/cve-2026-47701-opentelemetry-operator-arbitrary-file-disclosure-in"},{"cve":"CVE-2026-48496","cvss":6.2,"epss":0.0018,"slug":"cve-2026-48496-opentelemetry-ebpf-profiler-denial-of-service-in-processpidevents","title":"OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in versio","severity":"medium","exploited":false,"published_at":"2026-09-11T22:16:37.4+00:00","url":"https://junglewise.ai/threats/cve-2026-48496-opentelemetry-ebpf-profiler-denial-of-service-in-processpidevents"},{"cve":"CVE-2026-45404","cvss":5.9,"epss":0.0014,"slug":"cve-2026-45404-opentelemetry-go-unsynchronized-baggage-map-race-condition","title":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains","severity":"medium","exploited":false,"published_at":"2026-08-24T22:16:53.02+00:00","url":"https://junglewise.ai/threats/cve-2026-45404-opentelemetry-go-unsynchronized-baggage-map-race-condition"},{"cve":"CVE-2026-59892","cvss":7.5,"epss":0.0078,"slug":"cve-2026-59892-opentelemetry-opentelemetry-js-denial-of-service-in","title":"OpenTelemetry opentelemetry-js denial of service in JaegerPropagator","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:27.19+00:00","url":"https://junglewise.ai/threats/cve-2026-59892-opentelemetry-opentelemetry-js-denial-of-service-in"},{"cve":"CVE-2026-54712","cvss":5.3,"epss":0.0046,"slug":"cve-2026-54712-opentelemetry-java-instrumentation-dos-in-rmi-context-propagation","title":"OpenTelemetry Java Instrumentation DoS in RMI context propagation","severity":"medium","exploited":false,"published_at":"2026-07-01T22:16:50.187+00:00","url":"https://junglewise.ai/threats/cve-2026-54712-opentelemetry-java-instrumentation-dos-in-rmi-context-propagation"},{"cve":"CVE-2026-54704","cvss":6.5,"epss":0.0038,"slug":"cve-2026-54704-opentelemetry-java-instrumentation-information-disclosure-in-jdbc","title":"OpenTelemetry Java Instrumentation information disclosure in JDBC auto-instrumentation","severity":"medium","exploited":false,"published_at":"2026-07-01T22:16:50.05+00:00","url":"https://junglewise.ai/threats/cve-2026-54704-opentelemetry-java-instrumentation-information-disclosure-in-jdbc"},{"cve":"CVE-2026-54285","cvss":5.3,"epss":0.004,"slug":"cve-2026-54285-opentelemetry-opentelemetry-js-unbounded-memory-allocation-in-w3c","title":"OpenTelemetry opentelemetry-js unbounded memory allocation in W3C Baggage","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:47.077+00:00","url":"https://junglewise.ai/threats/cve-2026-54285-opentelemetry-opentelemetry-js-unbounded-memory-allocation-in-w3c"},{"cve":"CVE-2026-44967","cvss":5.3,"epss":0.0002,"slug":"cve-2026-44967-opentelemetry-cpp-memory-exhaustion-in-otlp-http-exporters","title":"OpenTelemetry-cpp memory exhaustion in OTLP HTTP exporters","severity":"medium","exploited":false,"published_at":"2026-06-12T16:16:27.973+00:00","url":"https://junglewise.ai/threats/cve-2026-44967-opentelemetry-cpp-memory-exhaustion-in-otlp-http-exporters"},{"cve":"CVE-2026-45287","cvss":2.1,"slug":"cve-2026-45287-opentelemetry-go-file-descriptor-leak-in-schema-parsefile","title":"OpenTelemetry-Go file descriptor leak in schema ParseFile","severity":"low","exploited":false,"published_at":"2026-06-04T16:16:38.69+00:00","url":"https://junglewise.ai/threats/cve-2026-45287-opentelemetry-go-file-descriptor-leak-in-schema-parsefile"},{"cve":"CVE-2026-41178","cvss":5.3,"slug":"cve-2026-41178-opentelemetry-go-denial-of-service-via-oversized-baggage-headers","title":"OpenTelemetry-Go Denial of Service via oversized baggage headers","severity":"medium","exploited":false,"published_at":"2026-06-04T16:16:37.297+00:00","url":"https://junglewise.ai/threats/cve-2026-41178-opentelemetry-go-denial-of-service-via-oversized-baggage-headers"},{"cve":"CVE-2026-45686","cvss":7.5,"slug":"cve-2026-45686-opentelemetry-ebpf-instrumentation-integer-overflow-in-memcached","title":"OpenTelemetry eBPF Instrumentation integer overflow in Memcached parser","severity":"high","exploited":false,"published_at":"2026-06-02T16:16:43.493+00:00","url":"https://junglewise.ai/threats/cve-2026-45686-opentelemetry-ebpf-instrumentation-integer-overflow-in-memcached"},{"cve":"CVE-2026-45685","cvss":7.5,"slug":"cve-2026-45685-opentelemetry-ebpf-instrumentation-denial-of-service-in-mongodb","title":"OpenTelemetry eBPF Instrumentation denial of service in MongoDB parser","severity":"high","exploited":false,"published_at":"2026-06-02T16:16:43.347+00:00","url":"https://junglewise.ai/threats/cve-2026-45685-opentelemetry-ebpf-instrumentation-denial-of-service-in-mongodb"},{"cve":"CVE-2026-45684","cvss":4.9,"slug":"cve-2026-45684-opentelemetry-ebpf-instrumentation-buffer-over-read-in-log","title":"OpenTelemetry eBPF Instrumentation buffer over-read in log enricher","severity":"medium","exploited":false,"published_at":"2026-06-02T16:16:43.187+00:00","url":"https://junglewise.ai/threats/cve-2026-45684-opentelemetry-ebpf-instrumentation-buffer-over-read-in-log"},{"cve":"CVE-2026-45683","cvss":3.8,"slug":"cve-2026-45683-opentelemetry-obi-kernel-memory-disclosure-in-java-tls-ioctl","title":"OpenTelemetry OBI kernel memory disclosure in Java TLS ioctl probe","severity":"low","exploited":false,"published_at":"2026-06-02T16:16:43.047+00:00","url":"https://junglewise.ai/threats/cve-2026-45683-opentelemetry-obi-kernel-memory-disclosure-in-java-tls-ioctl"},{"cve":"CVE-2026-45682","cvss":5.1,"slug":"cve-2026-45682-opentelemetry-ebpf-instrumentation-memory-leak-in-java-tls","title":"OpenTelemetry eBPF Instrumentation memory leak in Java TLS tracking","severity":"medium","exploited":false,"published_at":"2026-06-02T16:16:42.897+00:00","url":"https://junglewise.ai/threats/cve-2026-45682-opentelemetry-ebpf-instrumentation-memory-leak-in-java-tls"},{"cve":"CVE-2026-45681","cvss":5.9,"slug":"cve-2026-45681-opentelemetry-ebpf-instrumentation-out-of-bounds-read-in-message","title":"OpenTelemetry eBPF Instrumentation out-of-bounds read in message-buffer fallback","severity":"medium","exploited":false,"published_at":"2026-06-02T16:16:42.753+00:00","url":"https://junglewise.ai/threats/cve-2026-45681-opentelemetry-ebpf-instrumentation-out-of-bounds-read-in-message"},{"cve":"CVE-2026-45680","cvss":5.9,"slug":"cve-2026-45680-opentelemetry-ebpf-instrumentation-cpu-exhaustion-via-excessive","title":"OpenTelemetry eBPF Instrumentation CPU exhaustion via excessive iteration","severity":"medium","exploited":false,"published_at":"2026-06-02T16:16:42.603+00:00","url":"https://junglewise.ai/threats/cve-2026-45680-opentelemetry-ebpf-instrumentation-cpu-exhaustion-via-excessive"},{"cve":"CVE-2026-45679","cvss":6.5,"slug":"cve-2026-45679-opentelemetry-ebpf-instrumentation-information-disclosure-in","title":"OpenTelemetry eBPF Instrumentation information disclosure in Redis spans","severity":"medium","exploited":false,"published_at":"2026-06-02T16:16:42.43+00:00","url":"https://junglewise.ai/threats/cve-2026-45679-opentelemetry-ebpf-instrumentation-information-disclosure-in"},{"cve":"CVE-2026-45678","cvss":7.5,"slug":"cve-2026-45678-opentelemetry-obi-denial-of-service-in-postgres-protocol-parser","title":"OpenTelemetry OBI denial of service in Postgres protocol parser","severity":"high","exploited":false,"published_at":"2026-06-02T16:16:42.287+00:00","url":"https://junglewise.ai/threats/cve-2026-45678-opentelemetry-obi-denial-of-service-in-postgres-protocol-parser"}],"vendor":{"hub":true,"name":"Opentelemetry","slug":"opentelemetry","homepage":"https://opentelemetry.io","description":"Open standard for observability that defines APIs and SDKs for distributed tracing, metrics, and logging.","url":"https://junglewise.ai/threats/vendors/opentelemetry"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-33701","cvss":9.8,"epss":0.0093,"slug":"cve-2026-33701-opentelemetry-java-instrumentation-rce-via-unsafe-deserialization","title":"OpenTelemetry Java Instrumentation RCE via Unsafe Deserialization in RMI","severity":"critical","exploited":false,"published_at":"2026-03-27T01:16:19.313+00:00","url":"https://junglewise.ai/threats/cve-2026-33701-opentelemetry-java-instrumentation-rce-via-unsafe-deserialization"},{"cve":"CVE-2026-41433","cvss":8.4,"slug":"cve-2026-41433-opentelemetry-ebpf-instrumentation-privileged-java-agent","title":"OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIR","severity":"high","exploited":false,"published_at":"2026-04-24T20:16:27.803+00:00","url":"https://junglewise.ai/threats/cve-2026-41433-opentelemetry-ebpf-instrumentation-privileged-java-agent"},{"cve":"CVE-2026-42602","cvss":8.1,"epss":0.0003,"slug":"cve-2026-42602-opentelemetry-azureauthextension-authentication-bypass-via-token","title":"OpenTelemetry azureauthextension authentication bypass via token replay","severity":"high","exploited":false,"published_at":"2026-05-13T21:16:47.21+00:00","url":"https://junglewise.ai/threats/cve-2026-42602-opentelemetry-azureauthextension-authentication-bypass-via-token"},{"cve":"CVE-2026-47701","cvss":7.7,"epss":0.0046,"slug":"cve-2026-47701-opentelemetry-operator-arbitrary-file-disclosure-in","title":"The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator in","severity":"high","exploited":false,"published_at":"2026-09-14T16:17:11.54+00:00","url":"https://junglewise.ai/threats/cve-2026-47701-opentelemetry-operator-arbitrary-file-disclosure-in"},{"cve":"CVE-2026-59892","cvss":7.5,"epss":0.0078,"slug":"cve-2026-59892-opentelemetry-opentelemetry-js-denial-of-service-in","title":"OpenTelemetry opentelemetry-js denial of service in JaegerPropagator","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:27.19+00:00","url":"https://junglewise.ai/threats/cve-2026-59892-opentelemetry-opentelemetry-js-denial-of-service-in"},{"cve":"CVE-2026-44902","cvss":7.5,"epss":0.0049,"slug":"cve-2026-44902-opentelemetry-opentelemetry-js-denial-of-service-in-prometheus","title":"OpenTelemetry opentelemetry-js denial of service in Prometheus exporter","severity":"high","exploited":false,"published_at":"2026-05-27T15:16:29.313+00:00","url":"https://junglewise.ai/threats/cve-2026-44902-opentelemetry-opentelemetry-js-denial-of-service-in-prometheus"},{"cve":"CVE-2026-29181","cvss":7.5,"epss":0.0033,"slug":"cve-2026-29181-opentelemetry-opentelemetry-go-resource-exhaustion-in-baggage","title":"OpenTelemetry OpenTelemetry-Go resource exhaustion in baggage header extraction","severity":"high","exploited":false,"published_at":"2026-04-07T21:17:16.003+00:00","url":"https://junglewise.ai/threats/cve-2026-29181-opentelemetry-opentelemetry-go-resource-exhaustion-in-baggage"},{"cve":"CVE-2026-45686","cvss":7.5,"slug":"cve-2026-45686-opentelemetry-ebpf-instrumentation-integer-overflow-in-memcached","title":"OpenTelemetry eBPF Instrumentation integer overflow in Memcached parser","severity":"high","exploited":false,"published_at":"2026-06-02T16:16:43.493+00:00","url":"https://junglewise.ai/threats/cve-2026-45686-opentelemetry-ebpf-instrumentation-integer-overflow-in-memcached"},{"cve":"CVE-2026-45685","cvss":7.5,"slug":"cve-2026-45685-opentelemetry-ebpf-instrumentation-denial-of-service-in-mongodb","title":"OpenTelemetry eBPF Instrumentation denial of service in MongoDB parser","severity":"high","exploited":false,"published_at":"2026-06-02T16:16:43.347+00:00","url":"https://junglewise.ai/threats/cve-2026-45685-opentelemetry-ebpf-instrumentation-denial-of-service-in-mongodb"},{"cve":"CVE-2026-45678","cvss":7.5,"slug":"cve-2026-45678-opentelemetry-obi-denial-of-service-in-postgres-protocol-parser","title":"OpenTelemetry OBI denial of service in Postgres protocol parser","severity":"high","exploited":false,"published_at":"2026-06-02T16:16:42.287+00:00","url":"https://junglewise.ai/threats/cve-2026-45678-opentelemetry-obi-denial-of-service-in-postgres-protocol-parser"}],"generated_at":"2026-09-26T14:07:00.158513+00:00","technologies":[{"name":"Opentelemetry-Ebpf-Instrumentation","slug":"ebpf-instrumentation","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/ebpf-instrumentation"},{"name":"Opentelemetry Otelhttp","slug":"otelhttp","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/otelhttp"},{"name":"OpenTelemetry Go SDK","slug":"go-sdk","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/go-sdk"},{"name":"Opentelemetry-Go","slug":"opentelemetry-go","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/opentelemetry-go"},{"name":"Opentelemetry","slug":"opentelemetry","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/opentelemetry"},{"name":"Opentelemetry Java Instrumentation","slug":"java-instrumentation","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/java-instrumentation"}]}