CVE-2026-81192OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS Exploitation status Not known exploited Fix Not confirmed Affected product O opentelemetry-dotnet-contrib Published 09/08/2026 Severity High CVE-2026-45404OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access Exploitation status Public exploit Fix YesAffected product O opentelemetry-go Published 08/24/2026 Severity Medium CVE-2026-48504OpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagation Exploitation status Not known exploited Fix YesAffected product O opentelemetry-rust Published 07/17/2026 Severity Medium CVE-2026-59892OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header Exploitation status Public exploit Fix YesAffected product O opentelemetry-js Published 07/08/2026 Severity High CVE-2026-54712OpenTelemetry Javaagent RMI context propagation allows resource exhaustion Exploitation status Not known exploited Fix YesAffected product O opentelemetry-java-instrumentation Published 07/01/2026 Severity Medium CVE-2026-54704OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords Exploitation status Not known exploited Fix YesAffected product O opentelemetry-java-instrumentation Published 07/01/2026 Severity Medium CVE-2026-54285opentelemetry-js: Unbounded memory allocation in W3C Baggage propagation Exploitation status Not known exploited Fix YesAffected product O opentelemetry-js Published 06/22/2026 Severity Medium CVE-2026-44967opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response Exploitation status Public exploit Fix YesAffected product O opentelemetry-cpp Published 06/12/2026 Severity Medium CVE-2026-45287OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse Exploitation status Public exploit Fix Not confirmed Affected product G go.opentelemetry.io/otel/schema/v1.1 Published 06/04/2026 Severity Low CVE-2026-41178OpenTelemetry-Go's baggage parsing no longer caps raw header length Exploitation status Public exploit Fix Not confirmed Affected product G go.opentelemetry.io/otel/baggage Published 06/04/2026 Severity Medium CVE-2026-45686OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI Exploitation status Public exploit Fix YesAffected product O opentelemetry-ebpf-instrumentation Published 06/02/2026 Severity High CVE-2026-45685OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages Exploitation status Public exploit Fix YesAffected product O opentelemetry-ebpf-instrumentation Published 06/02/2026 Severity High CVE-2026-45684OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers Exploitation status Public exploit Fix YesAffected product O opentelemetry-ebpf-instrumentation Published 06/02/2026 Severity Medium CVE-2026-45683OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure Exploitation status Public exploit Fix YesAffected product O opentelemetry-ebpf-instrumentation Published 06/02/2026 Severity Low CVE-2026-45681OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size Exploitation status Public exploit Fix YesAffected product O opentelemetry-ebpf-instrumentation Published 06/02/2026 Severity Medium CVE-2026-45680OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU Exploitation status Public exploit Fix YesAffected product O opentelemetry-ebpf-instrumentation Published 06/02/2026 Severity Medium CVE-2026-45679OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages Exploitation status Public exploit Fix YesAffected product O opentelemetry-ebpf-instrumentation Published 06/02/2026 Severity Medium CVE-2026-45678OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads Exploitation status Public exploit Fix YesAffected product O opentelemetry-ebpf-instrumentation Published 06/02/2026 Severity High CVE-2026-45676OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent Exploitation status Public exploit Fix YesAffected product O opentelemetry-ebpf-instrumentation Published 06/02/2026 Severity Medium CVE-2026-45682OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals Exploitation status Public exploit Fix YesAffected product O opentelemetry-ebpf-instrumentation Published 06/02/2026 Severity Medium CVE-2026-45292opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation Exploitation status Not known exploited Fix YesAffected product O opentelemetry-java Published 05/28/2026 Severity High CVE-2026-44902opentelemetry-js: Prometheus exporter process crash via malformed HTTP request Exploitation status Public exploit Fix YesAffected product O opentelemetry-js Published 05/27/2026 Severity High CVE-2026-44213OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured Exploitation status Public exploit Fix YesAffected product O opentelemetry-dotnet-contrib Published 05/26/2026 Severity Medium CVE-2026-42602azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay Exploitation status Public exploit Fix Not confirmed Affected product O opentelemetry-collector-contrib Published 05/13/2026 Severity High CVE-2026-42191OpenTelemetry.Exporter.OpenTelemetryProtocol: Disk retry default temp path enables local blob injection for OTLP Exporter Exploitation status Not known exploited Fix YesAffected product O opentelemetry-dotnet Published 05/12/2026 Severity Medium CVE-2026-42348OpAMP client reads unbounded HTTP response bodies Exploitation status Not known exploited Fix YesAffected product O opentelemetry-dotnet-contrib Published 05/12/2026 Severity Medium CVE-2026-41484OpenTelemetry.Exporter.OneCollector vulnerable to denial of service via unbounded HTTP error response body Exploitation status Not known exploited Fix YesAffected product O opentelemetry-dotnet-contrib Published 05/06/2026 Severity Medium CVE-2026-41483Unbounded HTTP response body read in OpenTelemetry.Resources.Azure Exploitation status Not known exploited Fix YesAffected product O opentelemetry-dotnet-contrib Published 05/06/2026 Severity Medium CVE-2026-41310OpenTelemetry .NET Zipkin exporter has unbounded remote endpoint cache leading to memory growth Exploitation status Not known exploited Fix YesAffected product O opentelemetry-dotnet Published 05/06/2026 Severity Medium CVE-2026-41433OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIR Exploitation status Public exploit Fix YesAffected product O opentelemetry-ebpf-instrumentation Published 04/24/2026 Severity High CVE-2026-41173Unbounded HTTP response body read in OpenTelemetry.Sampler.AWS Exploitation status Not known exploited Fix YesAffected product O opentelemetry-dotnet-contrib Published 04/23/2026 Severity Medium CVE-2026-41078OpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path Exploitation status Not known exploited Fix Not confirmed Affected product O opentelemetry-dotnet Published 04/23/2026 Severity Medium CVE-2026-40894OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers Exploitation status Not known exploited Fix YesAffected product O opentelemetry-dotnet Published 04/23/2026 Severity Medium CVE-2026-40891OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling Exploitation status Not known exploited Fix YesAffected product O opentelemetry-dotnet Published 04/23/2026 Severity Medium CVE-2026-40182OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies Exploitation status Not known exploited Fix YesAffected product O opentelemetry-dotnet Published 04/23/2026 Severity Medium CVE-2026-39883OpenTelemetry-Go has an incomplete fix for CVE-2026-24051: BSD kenv command not using absolute path enables PATH hijacking Exploitation status Not known exploited Fix YesAffected product O opentelemetry-go Published 04/08/2026 Severity High CVE-2026-39882OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies Exploitation status Not known exploited Fix YesAffected product O opentelemetry-go Published 04/08/2026 Severity Medium CVE-2026-29181OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) Exploitation status Public exploit Fix YesAffected product O opentelemetry-go Published 04/07/2026 Severity High CVE-2026-33701OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution Exploitation status Not known exploited Fix Not confirmed Affected product O opentelemetry-java-instrumentation Published 03/27/2026 Severity Critical CVE-2026-24051OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking Exploitation status Not known exploited Fix YesAffected product O opentelemetry-go Published 02/02/2026 Severity High CVE-2025-27513OpenTelemetry .NET has a Denial of Service (DoS) Vulnerability in API Package Exploitation status Not known exploited Fix YesAffected product O opentelemetry-dotnet Published 03/05/2025 Severity High CVE-2024-45043OpenTelemetry Collector AWS Firehose Receiver Authentication Bypass Vulnerability Exploitation status Not known exploited Fix Not confirmed Affected product O opentelemetry-collector-contrib Published 08/28/2024 Severity Medium CVE-2024-42368open-telemetry has an Observable Timing Discrepancy Exploitation status Not known exploited Fix YesAffected product O opentelemetry-collector-contrib Published 08/13/2024 Severity Medium CVE-2024-36129OpenTelemetry Collector has a Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC Exploitation status Public exploit Fix YesAffected product O opentelemetry-collector Published 06/05/2024 Severity High CVE-2024-32028Sensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCore Exploitation status Not known exploited Fix Not confirmed Affected product O opentelemetry-dotnet Published 04/12/2024 Severity Medium CVE-2023-47108DoS vulnerability in otelgrpc (uncontrolled resource consumption) due to unbound cardinality metrics Exploitation status Public exploit Fix Not confirmed Affected product O opentelemetry-go-contrib Published 11/10/2023 Severity High CVE-2023-45142OpenTelemetry-Go Contrib has DoS vulnerability in otelhttp due to unbound cardinality metrics Exploitation status Not confirmed Fix Not confirmed Affected product O opentelemetry-go-contrib Published 10/12/2023 Severity High CVE-2023-43810opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics Exploitation status Not known exploited Fix YesAffected product O opentelemetry-python-contrib Published 10/06/2023 Severity High CVE-2023-39951Instrumentation for AWS SDK v2 captures email content when using Amazon Simple Email Service (SES) v1 API, exposing that content to the telemetry backend Exploitation status Public exploit Fix Not confirmed Affected product O opentelemetry-java-instrumentation Published 08/08/2023 Severity Medium CVE-2023-25151DoS vulnerability for high cardinality metrics in opentelemetry-go-contrib Exploitation status Public exploit Fix Not confirmed Affected product O opentelemetry-go-contrib Published 02/08/2023 Severity High