opentelemetry has 6 CVEs on record. Cadence is steady at roughly 3 per quarter. The busiest recent month was July 2026 with 3. The median CVSS is 6.8 (medium). None have a confirmed exploitation report. Most affected products: io.opentelemetry.javaagent:opentelemetry-javaagent (2), opentelemetry (2), @opentelemetry/core (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 3 prev 3
Products
- io.opentelemetry.javaagent:opentelemetry-javaagent 2
- opentelemetry 2
- @opentelemetry/core 1
- @opentelemetry/propagator-jaeger 1
Worst active — by depth score
CVE-2026-29181High· 7.5OpenTelemetry-Go is the Go implementation of OpenTelemetry53CVE-2026-59892High· 7.5OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header41CVE-2026-39883High· 7.0OpenTelemetry-Go is the Go implementation of OpenTelemetry39CVE-2026-54704Medium· 6.5OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords36CVE-2026-54712Medium· 5.3OpenTelemetry Javaagent RMI context propagation allows resource exhaustion29
opentelemetry vulnerabilities
CVEs affecting opentelemetry, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-54712Medium· 5.3OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
CVE-2026-54704Medium· 6.5OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
CVE-2026-59892High· 7.5OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
CVE-2026-54285Medium· 5.3OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
CVE-2026-39883High· 7.0OpenTelemetry-Go is the Go implementation of OpenTelemetry
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PAT…
CVE-2026-29181High· 7.5PoCOpenTelemetry-Go is the Go implementation of OpenTelemetry
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to ampli…