Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Opentelemetry

First CVE: Oct 6, 2023Active for: 3 yearsTotal CVEs: 32
24.9
VTI Score
Low

OpenTelemetry is an instrumentation framework and observability standard embedded across widely distributed tracing, metrics, and logging libraries, giving its vulnerability footprint an outsized downstream impact despite a modest direct product count. The vendor's disclosures cluster around resource-management and input-validation weaknesses—allocation without limits, excessive memory allocation, improper validation, uncontrolled resource consumption, and uncaught exceptions—reflecting the parsing and signal-handling demands of a data-collection middleware that processes untrusted telemetry inputs. These weakness classes are characteristic of components that sit between application code and backend observability systems, where a single flaw can cascade across numerous downstream projects that depend on the library. Defenders should treat OpenTelemetry updates as broadly applicable supply-chain events and inventory products that consume the library, since remediation often depends on coordinated rebuilds across multiple applications. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Opentelemetry over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2023
2 years ago
Most Recent CVE
Jun 12, 2026
42 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-45686HIGH
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overf
Jun 2, 20267.532NONO
CVE-2026-45685HIGH
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages ca
Jun 2, 20267.532NONO
CVE-2026-45678HIGH
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payl
Jun 2, 20267.532NONO
CVE-2026-41433HIGH
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java agent injection path allows a l
Apr 24, 20268.432NONO
CVE-2026-39883HIGH
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the
Apr 8, 20267.032NONO
CVE-2026-29181HIGH
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregate
Apr 7, 20267.532NONO
CVE-2026-42602HIGH
azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows any party who holds a single vali
May 13, 20268.131NONO
CVE-2026-45680HIGH
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations
Jun 2, 20267.530NONO
CVE-2026-42191HIGH
OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol) exporter implementation. From 1.8.0 to 1.15.2, the OTLP disk retry feature in OpenTelemetry.Export
May 12, 20267.830NONO
CVE-2026-24051HIGH
OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Dar
Feb 2, 20267.030NONO
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
50%
47%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local9 (28.1%)
Network20 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (9.4%)
Attack Complexity
Low22 (68.8%)
High10 (31.3%)
Unknown0 (0.0%)
User Interaction
None32 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low10 (31.3%)
High0 (0.0%)
None22 (68.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Opentelemetry.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Opentelemetry — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Opentelemetry's Products

View all 1 CNAs →

Top CWEs