Known vulnerabilities in opentelemetry-collector (Red Hat package)
Vendor:
Red Hat Inc.
Software CPE:
cpe:2.3:o:red_hat:opentelemetry-collector_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
19
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
0.152.1-1.el9_8
0.152.1-1.el10_2
0.144.0-2.el9_4
0.144.0-2.el9_6
0.144.0-2.el10_0
0.144.0-1.el9_7
0.144.0-1.el9_4
0.144.0-1.el9_6
0.144.0-1.el10_0
0.144.0-1.el10_1
0.135.0-3.el9_6
0.135.0-3.el10_0
0.135.0-3.el9_4
0.135.0-2.el10_0
0.135.0-2.el9_6
0.135.0-2.el9_4
0.135.0-2.el9_7
0.135.0-2.el10_1
0.107.0-8.el9_6
0.127.0-3.el10_0
0.127.0-2.el9_6
0.127.0-2.el9_4
0.127.0-1.el10_0
0.127.0-1.el9_6
0.127.0-1.el9_4
0.107.0-8.el9_4
0.107.0-7.el9_4
Vulnerabilities (19)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU140607 - Time-of-check Time-of-use (TOCTOU) Race Condition CVE-2026-32282 |
CWE-367 | Low | 0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 | 31.07.2026 |
SB2026073125 SB2026073160 SB2026073161 and 46 more |
||
| #VU140605 - Improper Certificate Validation CVE-2026-33810 |
CWE-295 | Medium | 0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 | 31.07.2026 |
SB2026073125 SB2026073183 SB2026073184 and 5 more |
||
| #VU140600 - Improper input validation CVE-2026-32281 |
CWE-20 | Medium | 0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 | 31.07.2026 |
SB2026073125 SB2026073183 SB2026073184 and 29 more |
||
| #VU140599 - Resource exhaustion CVE-2026-32280 |
CWE-400 | Medium | 0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 | 31.07.2026 |
SB2026073125 SB2026073160 SB2026073161 and 60 more |
||
| #VU136680 - Dependency on Vulnerable Third-Party Component CVE-2026-32283 |
CWE-1395 | Medium | 0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 | 02.07.2026 |
SB2026070218 SB2026070239 SB2026070240 and 56 more |
||
| #VU128730 - Improper Authorization CVE-2026-33186 |
CWE-285 | High | 0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 | 01.05.2026 |
SB2026050106 SB2026050107 SB2026050108 and 68 more |
||
| #VU125945 - Improper input validation CVE-2026-34986 |
CWE-20 | Medium | 0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 | 14.04.2026 |
SB2026041463 SB2026041464 SB2026041465 and 65 more |
||
| #VU124118 - Improper input validation CVE-2026-25679 |
CWE-20 | Medium | 0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0 | 19.03.2026 |
SB2026031903 SB2026031904 SB2026031905 and 126 more |
||
| #VU124034 - Resource exhaustion CVE-2025-61726 |
CWE-400 | Medium | 0.144.0-1.el9_4, 0.144.0-1.el9_6, 0.144.0-1.el9_7, 0.144.0-1.el10_0, 0.144.0-1.el10_1 | 16.03.2026 |
SB2026031636 SB2026031637 SB2026031638 and 139 more |
||
| #VU123129 - Improper Certificate Validation CVE-2025-68121 |
CWE-295 | High | 0.144.0-1.el9_4, 0.144.0-1.el9_6, 0.144.0-1.el9_7, 0.144.0-1.el10_0, 0.144.0-1.el10_1 | 23.02.2026 |
SB2026022333 SB2026030334 SB2026030343 and 108 more |
||
| #VU120232 - Uncontrolled Recursion CVE-2025-68156 |
CWE-674 | Medium | 0.135.0-2.el9_4, 0.135.0-2.el9_6, 0.135.0-2.el9_7, 0.135.0-2.el10_0, 0.135.0-2.el10_1 | 22.12.2025 |
SB2025122249 SB2025122250 SB2025122251 and 12 more |
||
| #VU119235 - Resource exhaustion CVE-2025-61729 |
CWE-400 | Medium | 0.135.0-3.el9_4, 0.135.0-3.el9_6, 0.135.0-3.el10_0 | 06.12.2025 |
SB2025120604 SB20251210172 SB20251210173 and 144 more |
||
| #VU112435 - Resource exhaustion CVE-2025-29786 |
CWE-400 | Medium | 0.107.0-7.el9_4 | 07.07.2025 |
SB2025070753 SB2025070755 SB2025121138 and 1 more |
||
| #VU110251 - Exposure of sensitive information to an unauthorized actor CVE-2025-4673 |
CWE-200 | Low | 0.127.0-2.el9_4, 0.127.0-2.el9_6, 0.127.0-3.el10_0 | 07.06.2025 |
SB2025060701 SB2025060702 SB2025061002 and 35 more |
||
| #VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-22871 |
CWE-444 | Medium | 0.127.0-1.el9_4, 0.127.0-1.el9_6, 0.127.0-1.el10_0 | 05.04.2025 |
SB2025040507 SB2025040508 SB2025040739 and 109 more |
||
| #VU105983 - Resource exhaustion CVE-2025-30204 |
CWE-400 | Medium | 0.107.0-8.el9_4 | 24.03.2025 |
SB2025032475 SB2025032730 SB2025040333 and 97 more |
||
| #VU105461 - Resource exhaustion CVE-2025-22868 |
CWE-400 | Medium | 0.107.0-7.el9_4 | 10.03.2025 |
SB2025031013 SB2025031015 SB2025031076 and 89 more |
||
| #VU105450 - Resource exhaustion CVE-2025-27144 |
CWE-400 | Medium | 0.107.0-7.el9_4 | 07.03.2025 |
SB2025030735 SB2025030736 SB2025030737 and 80 more |
||
| #VU103455 - Exposure of sensitive information to an unauthorized actor CVE-2024-45336 |
CWE-200 | Low | 0.107.0-7.el9_4 | 30.01.2025 |
SB2025013039 SB2025013043 SB2025013044 and 38 more |