VulnSea

opentelemetry-go vulnerabilities

CVEs whose affected-version data names the opentelemetry-go package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-81872Medium· 6.3PoC
6d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchronous export buffer…

Twilightopen-telemetry · opentelemetry-goEPSS 0.30%via NVD
CVE-2026-81869Medium· 5.1PoC
6d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing…

Twilightopen-telemetry · opentelemetry-goEPSS 0.13%via NVD
CVE-2026-81871Medium· 6.3
6d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate…

Sunlitopen-telemetry · opentelemetry-goEPSS 0.20%via NVD
CVE-2026-81870Low· 2.0PoC
6d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively includ…

Twilightopen-telemetry · opentelemetry-goEPSS 0.19%via NVD
opentelemetry-go vulnerabilities (CVEs) · VulnSea