Skip to content

cves: bump go.opentelemetry.io/otel to v1.44.0 to fix CVE-2026-41178#200

Merged
kezhenxu94 merged 2 commits into
apache:masterfrom
tetrateio:cve-2026-41178-bump-otel
Jun 15, 2026
Merged

cves: bump go.opentelemetry.io/otel to v1.44.0 to fix CVE-2026-41178#200
kezhenxu94 merged 2 commits into
apache:masterfrom
tetrateio:cve-2026-41178-bump-otel

Conversation

@tetrate-ci

Copy link
Copy Markdown
Contributor

Summary

Bumps go.opentelemetry.io/otel and related packages from v1.43.0 to v1.44.0 to fix CVE-2026-41178.

CVEs Fixed

CVE Severity Description Fix
CVE-2026-41178 MEDIUM DoS via baggage header parsing in go.opentelemetry.io/otel v1.43.0 Upgrade to v1.44.0+

Changes

  • go.opentelemetry.io/otel: v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/metric: v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/sdk: v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/trace: v1.43.0 → v1.44.0
  • go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc: v0.47.0 → v0.69.0 (for otel v1.44.0 compatibility)
  • go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp: v0.47.0 → v0.69.0 (for otel v1.44.0 compatibility)

@tetrate-ci tetrate-ci force-pushed the cve-2026-41178-bump-otel branch from 72426bb to 7880963 Compare June 10, 2026 01:33
Upgrades go.opentelemetry.io/otel and related packages to v1.44.0 to
address CVE-2026-41178 (DoS via baggage header parsing in v1.43.0).

Also bumps otelgrpc/otelhttp contrib to v0.69.0 for compatibility.
@tetrate-ci tetrate-ci force-pushed the cve-2026-41178-bump-otel branch from 7880963 to 85cd237 Compare June 10, 2026 01:35
@kezhenxu94 kezhenxu94 merged commit e690ea5 into apache:master Jun 15, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants