CVE-2026-45404Medium▾ SunlitOpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe fo…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent SetBaggageItem and correlation.MapFromContext calls on the same hooked bridgeSpan can trigger a fatal runtime error—such as concurrent map read and map write or concurrent map iteration and map write—terminating the process and causing denial of service. This issue is fixed in version 1.45.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
go.opentelemetry.io/otel/bridge/opentracing >= 0.11.0, < 1.45.0Patched in:
go.opentelemetry.io/otel/bridge/opentracing 1.45.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-45287Lowopentelemetry-go's Schema ParseFile leaks file descriptors on each parse
CVE-2026-43631High· 8.1llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary…
CVE-2026-61628High· 8.1nginx ignition is a user interface for the nginx web server
CVE-2023-35823High· 7.0An issue was discovered in the Linux kernel before 6.3.2
CVE-2025-55191Medium· 4.3github.com/argoproj/argo-cd/v2: github.com/argoproj/argo-cd/v3: Argo CD race condition leading to crash (CVE-2025-55191)
CVE-2026-20617High· 7.0A race condition was addressed with improved state handling