Hi,
The following vulnerability was published for golang-opentelemetry-otel.
CVE-2026-45404[0]:
| OpenTelemetry-Go is the Go implementation of OpenTelemetry. From
| version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan
| contains an unsynchronized extraBaggageItems map which can cause a
| panic. Because Go maps are not safe for concurrent read/write
| access, concurrent SetBaggageItem and correlation.MapFromContext
| calls on the same hooked bridgeSpan can trigger a fatal runtime
| error—such as concurrent map read and map write or concurrent map
| iteration and map write—terminating the process and causing denial
| of service. This issue is fixed in version 1.45.0.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-45404
https://www.cve.org/CVERecord?id=CVE-2026-45404
[1] https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-42cj-99w8-cp2p
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore