Known vulnerabilities in opentelemetry-collector (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:opentelemetry-collector_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 19
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting opentelemetry-collector (Red Hat package) opentelemetry-collector (Red Hat package) is affected by 19 known vulnerabilities: 2 high, 14 medium, 3 low Critical High Medium Low

Vulnerabilities (19)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140607 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-32282
CWE-367 Low
No
No
0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 31.07.2026 SB2026073125
SB2026073160
SB2026073161
and 46 more
#VU140605 - Improper Certificate Validation
CVE-2026-33810
CWE-295 Medium
No
No
0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 31.07.2026 SB2026073125
SB2026073183
SB2026073184
and 5 more
#VU140600 - Improper input validation
CVE-2026-32281
CWE-20 Medium
No
No
0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 31.07.2026 SB2026073125
SB2026073183
SB2026073184
and 29 more
#VU140599 - Resource exhaustion
CVE-2026-32280
CWE-400 Medium
No
No
0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 31.07.2026 SB2026073125
SB2026073160
SB2026073161
and 60 more
#VU136680 - Dependency on Vulnerable Third-Party Component
CVE-2026-32283
CWE-1395 Medium
No
No
0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 02.07.2026 SB2026070218
SB2026070239
SB2026070240
and 56 more
#VU128730 - Improper Authorization
CVE-2026-33186
CWE-285 High
No
No
0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 01.05.2026 SB2026050106
SB2026050107
SB2026050108
and 68 more
#VU125945 - Improper input validation
CVE-2026-34986
CWE-20 Medium
No
No
0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 14.04.2026 SB2026041463
SB2026041464
SB2026041465
and 65 more
#VU124118 - Improper input validation
CVE-2026-25679
CWE-20 Medium
No
No
0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 19.03.2026 SB2026031903
SB2026031904
SB2026031905
and 126 more
#VU124034 - Resource exhaustion
CVE-2025-61726
CWE-400 Medium
No
No
0.144.0-1.el9_4, 0.144.0-1.el9_6, 0.144.0-1.el9_7, 0.144.0-1.el10_0, 0.144.0-1.el10_1 16.03.2026 SB2026031636
SB2026031637
SB2026031638
and 139 more
#VU123129 - Improper Certificate Validation
CVE-2025-68121
CWE-295 High
No
No
0.144.0-1.el9_4, 0.144.0-1.el9_6, 0.144.0-1.el9_7, 0.144.0-1.el10_0, 0.144.0-1.el10_1 23.02.2026 SB2026022333
SB2026030334
SB2026030343
and 108 more
#VU120232 - Uncontrolled Recursion
CVE-2025-68156
CWE-674 Medium
No
No
0.135.0-2.el9_4, 0.135.0-2.el9_6, 0.135.0-2.el9_7, 0.135.0-2.el10_0, 0.135.0-2.el10_1 22.12.2025 SB2025122249
SB2025122250
SB2025122251
and 12 more
#VU119235 - Resource exhaustion
CVE-2025-61729
CWE-400 Medium
No
No
0.135.0-3.el9_4, 0.135.0-3.el9_6, 0.135.0-3.el10_0 06.12.2025 SB2025120604
SB20251210172
SB20251210173
and 144 more
#VU112435 - Resource exhaustion
CVE-2025-29786
CWE-400 Medium
No
No
0.107.0-7.el9_4 07.07.2025 SB2025070753
SB2025070755
SB2025121138
and 1 more
#VU110251 - Exposure of sensitive information to an unauthorized actor
CVE-2025-4673
CWE-200 Low
No
No
0.127.0-2.el9_4, 0.127.0-2.el9_6, 0.127.0-3.el10_0 07.06.2025 SB2025060701
SB2025060702
SB2025061002
and 35 more
#VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-22871
CWE-444 Medium
No
No
0.127.0-1.el9_4, 0.127.0-1.el9_6, 0.127.0-1.el10_0 05.04.2025 SB2025040507
SB2025040508
SB2025040739
and 109 more
#VU105983 - Resource exhaustion
CVE-2025-30204
CWE-400 Medium
No
No
0.107.0-8.el9_4 24.03.2025 SB2025032475
SB2025032730
SB2025040333
and 97 more
#VU105461 - Resource exhaustion
CVE-2025-22868
CWE-400 Medium
No
No
0.107.0-7.el9_4 10.03.2025 SB2025031013
SB2025031015
SB2025031076
and 89 more
#VU105450 - Resource exhaustion
CVE-2025-27144
CWE-400 Medium
No
No
0.107.0-7.el9_4 07.03.2025 SB2025030735
SB2025030736
SB2025030737
and 80 more
#VU103455 - Exposure of sensitive information to an unauthorized actor
CVE-2024-45336
CWE-200 Low
No
No
0.107.0-7.el9_4 30.01.2025 SB2025013039
SB2025013043
SB2025013044
and 38 more