Where
-Infinity
0

OpenTelemetry OpenTelemetry JavaScriptOpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header

Risk 43
Severity
7.5
First published (updated )

OpenTelemetry OpenTelemetry Java InstrumentationOpenTelemetry Javaagent RMI context propagation allows resource exhaustion

Risk 43
Severity
7.5
First published (updated )

OpenTelemetry OpenTelemetry Java InstrumentationOpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

Risk 38
Severity
6.5
First published (updated )

OpenTelemetry opentelemetry-cppopentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response

Risk 32
Severity
5.3
First published (updated )

go/go.opentelemetry.io/otel/schema/v1.0OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse

Risk 32
Severity
2.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/go.opentelemetry.io/otel/propagationOpenTelemetry-Go's baggage parsing no longer caps raw header length

Risk 27
Severity
5.3
First published (updated )

OpenTelemetry opentelemetry-javaopentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and …

Risk 33
Severity
7
First published (updated )

go/go.opentelemetry.io/obiOpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI

Risk 43
Severity
7.5
First published (updated )

go/go.opentelemetry.io/obiOpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages

Risk 43
Severity
7.5
First published (updated )

go/go.opentelemetry.io/obiOpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers

Risk 39
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/go.opentelemetry.io/obiOpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals

Risk 32
Severity
5.5
First published (updated )

go/go.opentelemetry.io/obiOpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure

Risk 20
Severity
3.8
First published (updated )

go/go.opentelemetry.io/obiOpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size

Risk 35
Severity
5.9
First published (updated )

go/go.opentelemetry.io/obiOpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU

Risk 43
Severity
7.5
First published (updated )

go/go.opentelemetry.io/obiOpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/go.opentelemetry.io/obiOpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages

Risk 40
Severity
6.5
First published (updated )

go/go.opentelemetry.io/obiOpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent

Risk 32
Severity
5.5
First published (updated )

go/github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextensionazureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay

Risk 60
Severity
8.1
First published (updated )

nuget/OpenTelemetry.OpAmp.ClientOpAMP client reads unbounded HTTP response bodies

Risk 43
Severity
7.5
First published (updated )

nuget/OpenTelemetry.Exporter.OpenTelemetryProtocolOpenTelemetry.Exporter.OpenTelemetryProtocol: Disk retry default temp path enables local blob injection for OTLP Exporter

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

nuget/OpenTelemetry.Exporter.OneCollectorOpenTelemetry.Exporter.OneCollector vulnerable to denial of service via unbounded HTTP error response body

Risk 35
Severity
5.9
First published (updated )

nuget/OpenTelemetry.Resources.AzureUnbounded HTTP response body read in OpenTelemetry.Resources.Azure

Risk 35
Severity
5.9
First published (updated )

nuget/OpenTelemetry.Exporter.ZipkinOpenTelemetry .NET Zipkin exporter has unbounded remote endpoint cache leading to memory growth

Risk 27
Severity
5.3
First published (updated )

OpenTelemetry OpenTelemetry eBPF InstrumentationOpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIR

Risk 59
Severity
8.4
First published (updated )

nuget/OpenTelemetry.ApiOpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

nuget/OpenTelemetryOpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling

Risk 32
Severity
5.3
First published (updated )

OpenTelemetry OpenTelemetry .NETOpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies

Risk 35
Severity
5.9
First published (updated )

OpenTelemetry OpenTelemetry .NETOpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path

Risk 35
Severity
5.9
First published (updated )

OpenTelemetry OpenTelemetry-GoOpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters…

Risk 33
Severity
7
First published (updated )

OpenTelemetry OpenTelemetry-GoOpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203