go.opentelemetry.io/otel
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting go.opentelemetry.io/otelpage 1 of 1
- CVE-2026-29181HIGHCVSS 7.5EG 7.5✓ Fixed in 1.41.02026-04-07
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify…
- CVE-2026-41178MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.44.02026-05-28
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized input…
Check whether go.opentelemetry.io/otel is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for go.opentelemetry.io/otel CVEs against the assets you own.
Start Free Scan →