Skip to content

chore: upgrade OpenTelemetry-Go exporters and SDK to v1.45.0 for CVE-2026-81870 - #28

Open
claude[bot] wants to merge 1 commit into
mainfrom
cve/otel-exporters-1.45.0
Open

claude[bot] wants to merge 1 commit into
mainfrom
cve/otel-exporters-1.45.0

Conversation

@claude

@claude claude Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Summary

Remediates CVE-2026-81870 (OpenTelemetry-Go: exporter config logging may leak endpoint URLs in info logs, severity LOW).

In OpenTelemetry Go 1.5.0–1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info event whose MarshalLog implementations recursively include span processor, exporter, and OTLP client configuration — disclosing the configured collector endpoint and the OTLP/HTTP Insecure flag to anyone with access to those logs. Upstream fix 3a1412d records exporter/client types instead of their configuration.

Changes

go.mod / go.sum only — no source changes were required, the upgrade is API-compatible.

Module Before After
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 v1.45.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 v1.45.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 v1.45.0
go.opentelemetry.io/otel/sdk v1.44.0 v1.45.0

Transitive bumps pulled in by go mod tidy as a consequence of the above: go.opentelemetry.io/proto/otlp v1.10.0 → v1.11.0, github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 → v2.29.0, and google.golang.org/genproto/googleapis/api to v0.0.0-20260803160001-6ac0973c030d. The already-upgraded go.opentelemetry.io/otel, otel/trace, otel/metric, and otel/bridge/opentracing were at v1.45.0 and are unchanged.

Verification

  • go list -m confirms all four affected modules resolve to v1.45.0; no vulnerable version remains in the module graph.
  • go mod verify — all modules verified (checksums intact).
  • go build ./... — clean.
  • go vet ./... — output is byte-identical to main (26 pre-existing findings in test files and cmd/zoekt-sourcegraph-indexserver).
  • go test ./... -short — the only failing package is internal/e2e, which fails identically on unmodified main in this environment (ctags-dependent scoring assertions). No regression introduced by this change.

Fixes SOU-2288

🤖 Generated with Claude Code


Note

Low Risk
Dependency-only, API-compatible bump in the OTLP tracing stack; main effect is safer startup logging, not behavioral changes to search or indexing logic.

Overview
Upgrades OpenTelemetry tracing dependencies in go.mod / go.sum only to address CVE-2026-81870, where older SDK versions could write OTLP collector endpoints and HTTP Insecure settings into internal Info logs when creating a TracerProvider.

go.opentelemetry.io/otel/exporters/otlp/otlptrace (plus gRPC/HTTP clients) move from v1.43.0 to v1.45.0, and go.opentelemetry.io/otel/sdk from v1.44.0 to v1.45.0, aligning with the already-at-v1.45.0 core otel modules. go mod tidy also refreshes transitive pins (proto/otlp, grpc-gateway/v2, genproto/googleapis/api). No application source changes; tracing still goes through internal/tracer/opentelemetry.go with the same APIs.

Reviewed by Cursor Bugbot for commit 8819d81. Bugbot is set up for automated code reviews on this repo. Configure here.

…2026-81870

Upgrades go.opentelemetry.io/otel/exporters/otlp/otlptrace,
otlptracegrpc, otlptracehttp (v1.43.0) and go.opentelemetry.io/otel/sdk
(v1.44.0) to v1.45.0, which stops recursively marshaling exporter and
client configuration into the internal "TracerProvider created" Info log.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants