Opentelemetry-Java-Instrumentation
Open-Telemetry · 4 CVEs
CVE-2026-54712
HIGH
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Jul 1, 2026
CVE-2026-54704
MEDIUM
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Jul 1, 2026
CVE-2026-33701
CRITICAL
OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution
Mar 27, 2026
CVE-2023-39951
MEDIUM
Instrumentation for AWS SDK v2 captures email content when using Amazon Simple Email Service (SES) v1 API, exposing tha…
Aug 8, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-54712 | OpenTelemetry Javaagent RMI context propagation allows resource exhaustion | HIGH | 0.46% | Jul 1, 2026 |
| CVE-2026-54704 | OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords | MEDIUM | 0.38% | Jul 1, 2026 |
| CVE-2026-33701 | OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution | CRITICAL | 1.11% | Mar 27, 2026 |
| CVE-2023-39951 | Instrumentation for AWS SDK v2 captures email content when using Amazon Simple Email Service (SES) v1 API, exposing that content to the telemetry backend | MEDIUM | 0.84% | Aug 8, 2023 |
Showing 1 to 4 of 4 CVEs