- Package:
- src:golang-opentelemetry-otel
- Source:
- src:golang-opentelemetry-otel
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-02 22:21:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for golang-opentelemetry-otel. CVE-2026-41178[0]: | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions | 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` | to process arbitrarily large/invalid baggage headers and log errors, | enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix | the issue. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-41178 https://www.cve.org/CVERecord?id=CVE-2026-41178 [1] https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835 [2] https://github.com/open-telemetry/opentelemetry-go/pull/7880 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1139167 in golang-opentelemetry-otel reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/go-team/packages/golang-opentelemetry-otel/-/commit/7f2d2305ffc666f566d033609cfb1810b7174773 ------------------------------------------------------------------------ New upstream version 1.44.0, fixing CVE-2026-45287 and CVE-2026-41178 - CVE-2026-45287: file descriptor leak in schema ParseFile (Closes: #1139168) - CVE-2026-41178: DoS via oversized baggage headers (Closes: #1139167) - Bump Breaks for prometheus-alertmanager-dev and prometheus-dev due to semconv schema URL conflict (v1.40.0 vs v1.41.0) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1139167
We believe that the bug you reported is fixed in the latest version of
golang-opentelemetry-otel, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1139167@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Juan Manuel Méndez Rey <juan.mendezr@proton.me> (supplier of updated golang-opentelemetry-otel package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 20 Sep 2026 21:58:45 +0200
Source: golang-opentelemetry-otel
Architecture: source
Version: 1.46.0-1~exp1
Distribution: experimental
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Juan Manuel Méndez Rey <juan.mendezr@proton.me>
Closes: 1139167 1139168
Changes:
golang-opentelemetry-otel (1.46.0-1~exp1) experimental; urgency=medium
.
* Team upload.
* Upload to experimental to stage the 1.46 transition, which also needs
golang-opentelemetry-contrib, prometheus-alertmanager and prometheus.
* New upstream version 1.46.0
- Adds attribute.MapValue and switches go.opentelemetry.io/otel/log
to attribute.Value/attribute.KeyValue. Needed by siso, which cannot
move past 1.5.22 without it (see #1141687).
* Fix CVE-2026-45287: file descriptor leak in schema ParseFile.
(Closes: #1139168)
* Fix CVE-2026-41178: DoS via oversized baggage headers. (Closes:
#1139167)
* debian/control: bump Breaks for prometheus-alertmanager-dev and
prometheus-dev: sdk/resource now uses semconv v1.43.0, older versions
fail tracer provider setup with a conflicting schema URL.
* debian/control: build against golang-github-cespare-xxhash-v2-dev,
which ships the module at github.com/cespare/xxhash/v2, the path the
import in go.mod resolves to.
* debian/control: add back golang-github-masterminds-semver-dev to
Build-Depends and Depends. schema/internal imports
github.com/Masterminds/semver/v3, so without it the autopkgtest fails
to build the package.
* debian/salsa-ci.yml: use the standard Salsa CI pipeline and drop
debian/gitlab-ci.yml, which only ran the pkg-go archive test.
* debian/patches: drop 0001-Fix-import-comment.patch, upstream removed
the import comment.
* debian/watch: use the GitHub refs API, so stable vX.Y.Z tags are not
hidden by per-module and pre-release tags.
Checksums-Sha1:
16587e70360e022fbf67af69eeba024ffa15ff51 2705 golang-opentelemetry-otel_1.46.0-1~exp1.dsc
8046c38187747dfc48bdfcc6b45a9df2b551f725 1217036 golang-opentelemetry-otel_1.46.0.orig.tar.xz
809b63270330eba941fb429bf98118b9508ff8a0 5304 golang-opentelemetry-otel_1.46.0-1~exp1.debian.tar.xz
a3bb105b7f71d76bc69fd9eb6c690106ccb12256 6533 golang-opentelemetry-otel_1.46.0-1~exp1_source.buildinfo
Checksums-Sha256:
bf5bda367130a0458da3439ba58d60dda2ed6d96f0500343b91d46e5729dbd3a 2705 golang-opentelemetry-otel_1.46.0-1~exp1.dsc
30beb6ac0156d94546961e8248c4eba8dda2989e429a79e5c68346ba2bde379e 1217036 golang-opentelemetry-otel_1.46.0.orig.tar.xz
15c5dc79db572f2628592dae98d54d902b022f0215025a05cc7fea2022e31e60 5304 golang-opentelemetry-otel_1.46.0-1~exp1.debian.tar.xz
812164ae724e0a5d95c56bd968bc651b40e910a2047787eb34c835a78158e915 6533 golang-opentelemetry-otel_1.46.0-1~exp1_source.buildinfo
Files:
2761a38e645e03eb63e26ddff9942383 2705 golang optional golang-opentelemetry-otel_1.46.0-1~exp1.dsc
3233f65a14378eb19c9c2aed9bc81c19 1217036 golang optional golang-opentelemetry-otel_1.46.0.orig.tar.xz
f90253b01a8374ed2a24e02d5c6ffa9c 5304 golang optional golang-opentelemetry-otel_1.46.0-1~exp1.debian.tar.xz
f14abad04decce5b18b576f9f65e8e44 6533 golang optional golang-opentelemetry-otel_1.46.0-1~exp1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE703UlH90QYpfEyJV58vhUqwX+XMFAmq5ducACgkQ58vhUqwX
+XNoDRAAlgb6LjSMLl9BFFVPXLv2lzQy71Jwtl5BAcIyJ/pfLTq5XqSgoWO4Fix8
061MYDL++CMglWqE+iRI7CiGwbp/SEtcwk/k/Qi4Vb/7Rr5fNxkwV5hVSuffq2fe
1lnA6lDv00RJyW525qv1BF1Iwbn89MbcnHeBa+ZvB3ogvOm6dCGskzGFaVs1/HUq
1kARcel1L7judwQL2kkI/YpH+532TY7YACjh+E0P2H18e9B9OcigOIGHSqzG7iet
IL4WEFCLTDL7SmSBYsfi4gVLyLfUQCtpd3QaLvQu00tE9uMQakWVBjHZ8BuhR3AE
RNu+ms7OnHfjgnhLes7cpuqRbMRCyt/cQcAZyKOCBstdEubuskP03rmUfiIn8IgT
9/VzOQDouTmeJN/vYjRfNSHuYWg6ldVJ4vBdfL0Sk17OraqkuYC2CsC6Y/UYOon4
jctinpfNlhLHBOlEwTp30eghlZI7C0V2d6IigtnzjxZW5GEbgIHyCOri1AVZyV5c
ISKDf2FlGvW2BpHfjzzDCZVgJA09wjP9F/E+LAxztOwQ+ieuIM49znf1yZAbGH9q
zO4/g51SFFhKFTlZYaLV9xdEJ+eVEB6plniaV1zuRwlaoi8A4erFmyVYACXe1GKi
qsehspP0/630v94UStfqM2Et+yVUXlCUkiGeZFbIho9nzxo3gnA=
=LYtf
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
golang-opentelemetry-otel, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1139167@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Reinhard Tartler <siretart@tauware.de> (supplier of updated golang-opentelemetry-otel package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 02 Oct 2026 17:52:31 -0400
Source: golang-opentelemetry-otel
Architecture: source
Version: 1.46.0-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Reinhard Tartler <siretart@tauware.de>
Closes: 1139167 1139168
Changes:
golang-opentelemetry-otel (1.46.0-2) unstable; urgency=medium
.
* Team upload.
.
[ Juan Manuel Méndez Rey ]
* Upload to unstable. No changes since 1.46.0-1~exp1, which has been in
experimental since 2026-09-27 together with golang-opentelemetry-contrib
1.46.0-1~exp1.
.
[ Reinhard Tartler ]
* d/lintian-overrides: suppress package-contains-documentation-outside-usr-share-doc
* d/patches: clean up and standardize DEP-3 headers
* debian/control: upgrade to debhelper-compat (= 14)
.
golang-opentelemetry-otel (1.46.0-1) unstable; urgency=medium
.
* Team upload.
[ Mathias Gibbens ]
* Cleanup DH_GOLANG_EXCLUDES and DH_GOLANG_INSTALL_EXTRA
* Cleanup Build-Depends and Depends
.
[ Andrew Lee (李健秋) ]
* debian/watch: switch to version 5.
* New upstream version 1.44.0
* debian/control: update dependency to matches with go.mod.
* Drop legacy patch.
* debian/control: switch to Module-Aware builds via dh-go.
* New upstream version 1.46.0
* debian/rules: do not cut down dependency with DH_GOLANG_EXCLUDES.
* debian/rules: drop debhelper's buildsystem option as it's been
specified in debian/control.
* add-missing-depends.patch: fix FTBFS in tests.
.
golang-opentelemetry-otel (1.46.0-1~exp1) experimental; urgency=medium
.
* Team upload.
* Upload to experimental to stage the 1.46 transition, which also needs
golang-opentelemetry-contrib, prometheus-alertmanager and prometheus.
* New upstream version 1.46.0
- Adds attribute.MapValue and switches go.opentelemetry.io/otel/log
to attribute.Value/attribute.KeyValue. Needed by siso, which cannot
move past 1.5.22 without it (see #1141687).
* Fix CVE-2026-45287: file descriptor leak in schema ParseFile.
(Closes: #1139168)
* Fix CVE-2026-41178: DoS via oversized baggage headers. (Closes:
#1139167)
* debian/control: bump Breaks for prometheus-alertmanager-dev and
prometheus-dev: sdk/resource now uses semconv v1.43.0, older versions
fail tracer provider setup with a conflicting schema URL.
* debian/control: build against golang-github-cespare-xxhash-v2-dev,
which ships the module at github.com/cespare/xxhash/v2, the path the
import in go.mod resolves to.
* debian/control: add back golang-github-masterminds-semver-dev to
Build-Depends and Depends. schema/internal imports
github.com/Masterminds/semver/v3, so without it the autopkgtest fails
to build the package.
* debian/salsa-ci.yml: use the standard Salsa CI pipeline and drop
debian/gitlab-ci.yml, which only ran the pkg-go archive test.
* debian/patches: drop 0001-Fix-import-comment.patch, upstream removed
the import comment.
* debian/watch: use the GitHub refs API, so stable vX.Y.Z tags are not
hidden by per-module and pre-release tags.
Checksums-Sha1:
17bcd7ae8383d7635ecbcf5679294732dae308e2 2842 golang-opentelemetry-otel_1.46.0-2.dsc
ac80874058709966323c581739e27355c524affe 5264 golang-opentelemetry-otel_1.46.0-2.debian.tar.xz
Checksums-Sha256:
c38367bd32d413a3dc8276fb0ccec5318914ab4065de81697b440eff01c5bf1c 2842 golang-opentelemetry-otel_1.46.0-2.dsc
fa3eedf337a041ae7ac34b896de38c293058dee4980cbc70be8d21f99814eb30 5264 golang-opentelemetry-otel_1.46.0-2.debian.tar.xz
Files:
8cd46e72edb6989d0b106a90fadcfcdd 2842 golang optional golang-opentelemetry-otel_1.46.0-2.dsc
785adcfc79bdf15e2336e98b5d69d145 5264 golang optional golang-opentelemetry-otel_1.46.0-2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCgAyFiEEMN59F2OrlFLH4IJQSadpd5QoJssFAmrAKJwUHHNpcmV0YXJ0
QHRhdXdhcmUuZGUACgkQSadpd5QoJstd8w/+LoYDyR09A89987g8CqQcwuI8qEDP
WZEc+Wq2BI77pBQ2Uhy1rOyxgIIxFL1p6qcDONmOBo1isryedX4ktNYSpPZCjwL9
mXiGQK7nKjEyAudRNe7Tccf1GdzOJlAH/uPAZeuutNMBJoAQzi528h5ZzPTC588W
p9/Abv91x8psxXDFjQpTWLccpuWcMaS7UIHi+9RLfuuhoJk7nzZMq/rSM8fUoq9m
nms2YvSxZAjcPfQLI3Tlid/CinzmJOpwFL94VLjvL0EfKFabmJKL2Fu6IcFkaUiR
ZXMiky9ejY/c7u6HczXVZ2z+1Ao0Y5W58U3FOOLboLSHMU6ujkbiX2P6v8j7muRm
hkyRCWGmr0szojll4CsJ272SxoMNqxt/W1z5wFO93TqTXHA+o6H7SkSGP+da+dN4
GRwwAVI0lGFYNRPlG/6zryN/hzrU1IDMy7uWgzZA4uPvzl0BSboHCyde64JT5PI5
cfqS9O4xoAemHrmhfAwXhliF8rzh8octUYaoW6vN0dxSLZbBVnCMhaKRRt9Zl+3h
gMMktalylxStOi7TwYhHVIiLF44amoDzxsY0rXNZ5eUgZoUt50KeINeBKGz3dh6Z
5r0mJJT9DBIPIaW8eLPB0apv1oiHmTtjREwqGHJG9hh/ppA/aSA9Nh9FYGUOui2t
9FfBgaabFK3UkK4=
=jTKz
-----END PGP SIGNATURE-----