Skip to content

fix(deps): bump go.opentelemetry.io/otel to v1.44.0 for CVE-2026-41178 - #384

Open
dbkreling wants to merge 1 commit into
openshift:mainfrom
dbkreling:fix/CVE-2026-41178
Open

fix(deps): bump go.opentelemetry.io/otel to v1.44.0 for CVE-2026-41178#384
dbkreling wants to merge 1 commit into
openshift:mainfrom
dbkreling:fix/CVE-2026-41178

Conversation

@dbkreling

@dbkreling dbkreling commented Sep 2, 2026

Copy link
Copy Markdown

Summary

Bumps go.opentelemetry.io/otel from v1.43.0 to v1.44.0 to resolve CVE-2026-41178.

CVE: CVE-2026-41178
Vulnerable range: v1.43.0 (raw-length rejection removed in baggage parsing)
Fixed in: v1.44.0
Jira ticket: KATA-5830

OpenTelemetry-Go versions 1.41.0 and 1.43.0 removed raw-length rejection in Parse, enabling DoS via oversized baggage headers.


This PR was created by the kata-bug-triage skill and supervised by Daniel Kreling.

Signed-off-by: Daniel Kreling <dkreling@redhat.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 2, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: f4ccc92f-e8d7-4e83-b6e7-47c09aa7ba8f


Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant