Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.8) | 0.24% | — | Opentelemetry Instrumentation Cassandra DriverAIOpentelemetry Instrumentation KnexAIOpentelemetry Instrumentation MongooseAIOpentelemetry Instrumentation MysqlAI+4 | 2/10/2026 | 6/10/2026 | OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose,… | |
| Pendiente de análisis | Media (6.3) | 0.38% | — | Opentelemetry GOAI | 16/9/2026 | 30/9/2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchronous export buffer while the exporter is backpressured. NewBatchingProcessor wraps the exporter with… | |
| Pendiente de análisis | Media (6.3) | 0.20% | — | Opentelemetry-goAI | 16/9/2026 | 30/9/2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS into cfg.tlsCfg, but newGRPCDialOptions… | |
| Pendiente de análisis | Media (5.1) | 0.18% | — | Opentelemetry GOAI | 16/9/2026 | 30/9/2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing the valid Unicode replacement character U+FFFD. safeTruncateValidUTF8 treats the… | |
| Aplazada | Baja (2) | 0.19% | — | Opentelemetry-goAI | 16/9/2026 | 30/9/2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call… | |
| Pendiente de análisis | Media (6.9) | 0.70% | — | Opentelemetry Collector ContribAI | 15/9/2026 | 30/9/2026 | The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiver/githubreceiver/trace_receiver.go handleReq() does not check those headers on… | |
| Aplazada | Media (5.3) | 0.42% | — | Fluent-plugin-opentelemetryAIFluentdAI | 15/9/2026 | 30/9/2026 | fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads into memory without enforcing maximum size thresholds. When an OpenTelemetry ingestion endpoint… | |
| Pendiente de análisis | Media (5.3) | 0.44% | — | Opentelemetry Sentry ExporterAI | 14/9/2026 | 25/9/2026 | OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter reads the remote OTLP sender-controlled service.name resource attribute in… | |
| Pendiente de análisis | Alta (7.7) | 0.46% | — | Opentelemetry OperatorAI | 14/9/2026 | 25/9/2026 | The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor endpoint's bearerTokenFile value as… | |
| Pendiente de análisis | Media (6.2) | 0.18% | — | Opentelemetry Ebpf ProfilerAI | 11/9/2026 | 25/9/2026 | OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to open a nonregular mapping file, such as a FIFO, and block indefinitely, preventing… | |
| Pendiente de análisis | Alta (7.7) | 0.47% | — | Redhat Multicluster Observability AddonAIRedhat Opentelemetry CollectorAIRedhat Cluster LOG ForwarderAI | 11/9/2026 | 21/9/2026 | A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on… | |
| Aplazada | Alta (7) | 0.18% | — | Opentelemetry Resources HostAI | 8/9/2026 | 10/9/2026 | `OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by… | |
| Aplazada | Media (5.9) | 0.14% | — | Opentelemetry-goAI | 24/8/2026 | 9/9/2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent SetBaggageItem and… | |
| Pendiente de análisis | Media (5.3) | 0.42% | — | Opentelemetry RustAI | 17/7/2026 | 23/7/2026 | OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unnecessary CPU work and short-lived heap… | |
| Pendiente de análisis | Alta (7.5) | 0.78% | — | Opentelemetry Propagator JaegerAI | 8/7/2026 | 10/7/2026 | OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed percent-encoded… | |
| Analizada | Alta (7.5) | 0.46% | — | Linuxfoundation Opentelemetry Instrumentation FOR Java | 1/7/2026 | 6/7/2026 | OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, the RMI context propagation payload reader limits the number of context entries but does not limit the aggregate size of the strings read from the stream. An attacker who… | |
| Analizada | Media (6.5) | 0.38% | — | Linuxfoundation Opentelemetry Instrumentation FOR Java | 1/7/2026 | 6/7/2026 | OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can… | |
| Analizada | Media (5.3) | 0.40% | — | Opentelemetry | 22/6/2026 | 27/8/2026 | opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size limits when parsing inbound baggage HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and 180 entries; these limits were only enforced on… | |
| Analizada | Media (5.3) | 0.30% | — | Opentelemetry | 12/6/2026 | 17/6/2026 | OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled… | |
| Analizada | Baja (2.1) | 0.18% | — | Opentelemetry Telemetry Schema Files | 4/6/2026 | 22/7/2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1.0` and `go.opentelemetry.io/otel/schema/v1.1` leaks one file descriptor on each successful `ParseFile` call. `ParseFile` opens the schema file and passes it to `Parse` without closing it; repeated… | |
| Analizada | Media (5.3) | 0.34% | — | Opentelemetry | 4/6/2026 | 22/7/2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue. | |
| Analizada | Alta (7.5) | 0.52% | — | Opentelemetry Ebpf Instrumentation | 2/6/2026 | 22/7/2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands… | |
| Analizada | Alta (7.5) | 0.63% | — | Opentelemetry Ebpf Instrumentation | 2/6/2026 | 22/7/2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry agent and cause a… | |
| Analizada | Media (5.3) | 0.18% | — | Opentelemetry Ebpf Instrumentation | 2/6/2026 | 22/7/2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by reading only the first iovec entry but using the total iov_iter.count as the copy length. When log injection is enabled, a… | |
| Analizada | Baja (3.8) | 0.18% | — | Opentelemetry Ebpf Instrumentation | 2/6/2026 | 22/7/2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_probe_read instead of bpf_probe_read_user. An instrumented local process can therefore point OBI at kernel memory and… |