[Git][security-tracker-team/security-tracker][master] Add new golang-opentelemetry-otel issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 20 10:21:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a5096482 by Salvatore Bonaccorso at 2026-09-20T11:19:43+02:00
Add new golang-opentelemetry-otel issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4820,13 +4820,30 @@ CVE-2026-85128 (The Choose User Role at Registration WordPress plugin before 1.3
 CVE-2026-82561 (Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-81872 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to v ...)
-	TODO: check
+	- golang-opentelemetry-otel <unfixed>
+	NOTE: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hjf4-fphr-2h65
+	NOTE: https://github.com/open-telemetry/opentelemetry-go/issues/6797
+	NOTE: https://github.com/open-telemetry/opentelemetry-go/pull/8620
+	NOTE: Introduced with: https://github.com/open-telemetry/opentelemetry-go/commit/4af9c20a80182e5ac8212182d3ba970d0d558a45 (v1.26.0)
+	NOTE: Fixed by: https://github.com/open-telemetry/opentelemetry-go/commit/ba71b09e6ed272e93a669aeaec1e98b1df4cc582 (v1.45.0)
 CVE-2026-81871 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to v ...)
-	TODO: check
+	- golang-opentelemetry-otel <unfixed>
+	NOTE: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x
+	NOTE: Introduced with: https://github.com/open-telemetry/opentelemetry-go/commit/d99c76fa32fbbcf3e1e0cee4c49a7f181b0697bb (v1.28.0)
+	NOTE: Fixed by: https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c (v1.45.0)
 CVE-2026-81870 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. From versi ...)
-	TODO: check
+	- golang-opentelemetry-otel <unfixed>
+	NOTE: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg
+	NOTE: https://github.com/open-telemetry/opentelemetry-go/pull/8438
+	NOTE: Introduced with: https://github.com/open-telemetry/opentelemetry-go/commit/a1fff3c2588c783d1f3f6fd2315aa2660fc6d330 (v1.5.0)
+	NOTE: Fixed by: https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38 (v1.45.0)
 CVE-2026-81869 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. From versi ...)
-	TODO: check
+	- golang-opentelemetry-otel 1.43.0-1
+	NOTE: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-p9f8-wvj8-2fg8
+	NOTE: https://github.com/open-telemetry/opentelemetry-go/issues/5996
+	NOTE: https://github.com/open-telemetry/opentelemetry-go/pull/5997
+	NOTE: Introduced with: https://github.com/open-telemetry/opentelemetry-go/commit/49a653682f1257a66771324e818f6a83fb13d62b (v1.10.0
+	NOTE: Fixed by: https://github.com/open-telemetry/opentelemetry-go/commit/e016a78c9f5b24a1c2beeaad47686c2f2213f49a (v1.33.0)
 CVE-2026-81866 (Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration updat ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-81546 (The Affinity by Canva application before 3.3.0 (September 2026 release ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a509648278ebc27463e23109f4ca56f4c779337b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a509648278ebc27463e23109f4ca56f4c779337b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/4f9f723f/attachment.htm>


More information about the debian-security-tracker-commits mailing list