Common Vulnerabilities and Exposures

This is a list of reported Common Vulnerabilities and Exposures (CVEs) across all repositories in the OpenTelemetry organization on GitHub. The raw data is stored in the sig-security repository, and it is refreshed daily.

CVE IDIssue SummarySeverityRepository
CVE-2024-36129Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPChighopentelemetry-collector
CVE-2024-32028OpenTelemetry.Instrumentation.Http & OpenTelemetry.Instrumentation.AspNetCore packages log potentially sensitive query string parameters by defaultmediumopentelemetry-dotnet
CVE-2023-47108DoS vulnerability in otelgrpc (uncontrolled resource consumption) due to unbound cardinality metrics highopentelemetry-go-contrib
CVE-2023-39951Instrumentation for AWS SDK v2 captures email content when using Amazon Simple Email Service (SES) v1 API, exposing that content to the telemetry backendmediumopentelemetry-java-instrumentation
CVE-2023-38704Unsanitized user controlled input in module generationhighopentelemetry-js