Skip to content

Bump otel/sdk to v1.40.0 (CVE-2026-24051)#3

Open
owenwahlgren wants to merge 1 commit intomainfrom
fix/cve-2026-24051-otel-sdk
Open

Bump otel/sdk to v1.40.0 (CVE-2026-24051)#3
owenwahlgren wants to merge 1 commit intomainfrom
fix/cve-2026-24051-otel-sdk

Conversation

@owenwahlgren
Copy link
Copy Markdown
Collaborator

Summary

  • Bumps go.opentelemetry.io/otel/sdk to v1.40.0 across all 3 Go modules
  • Fixes CVE-2026-24051 / GHSA-9h8m-3fm2-qjrq (arbitrary code execution via PATH hijacking)
  • Resolves Dependabot alerts #17, #18, #19

Test plan

  • make test-unit passes

Fixes GHSA-9h8m-3fm2-qjrq (PATH hijacking) across all three Go modules.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant