OpenTelemetry is an instrumentation framework and observability standard embedded across widely distributed tracing, metrics, and logging libraries, giving its vulnerability footprint an outsized downstream impact despite a modest direct product count. The vendor's disclosures cluster around resource-management and input-validation weaknesses—allocation without limits, excessive memory allocation, improper validation, uncontrolled resource consumption, and uncaught exceptions—reflecting the parsing and signal-handling demands of a data-collection middleware that processes untrusted telemetry inputs. These weakness classes are characteristic of components that sit between application code and backend observability systems, where a single flaw can cascade across numerous downstream projects that depend on the library. Defenders should treat OpenTelemetry updates as broadly applicable supply-chain events and inventory products that consume the library, since remediation often depends on coordinated rebuilds across multiple applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opentelemetry over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45686HIGH OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overf | Jun 2, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-45685HIGH OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages ca | Jun 2, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-45678HIGH OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payl | Jun 2, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-41433HIGH OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java agent injection path allows a l | Apr 24, 2026 | 8.4 | 32 | NO | NO |
CVE-2026-39883HIGH OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the | Apr 8, 2026 | 7.0 | 32 | NO | NO |
CVE-2026-29181HIGH OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregate | Apr 7, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-42602HIGH azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows any party who holds a single vali | May 13, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-45680HIGH OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations | Jun 2, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-42191HIGH OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol) exporter implementation. From 1.8.0 to 1.15.2, the OTLP disk retry feature in OpenTelemetry.Export | May 12, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-24051HIGH OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Dar | Feb 2, 2026 | 7.0 | 30 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opentelemetry.
Media articles that mention a CVE ID that affects a product developed by Opentelemetry — matched by CVE ID, not by vendor name.