Skip to content

fix(core): bump OpenTelemetry Go SDK to v1.40.0 (CVE-2026-24051)#2057

Draft
loktev-d wants to merge 4 commits intomainfrom
fix/core/cve-2026-24051
Draft

fix(core): bump OpenTelemetry Go SDK to v1.40.0 (CVE-2026-24051)#2057
loktev-d wants to merge 4 commits intomainfrom
fix/core/cve-2026-24051

Conversation

@loktev-d
Copy link
Contributor

@loktev-d loktev-d commented Mar 4, 2026

Description

Fix CVE-2026-24051 by bumping go.opentelemetry.io/otel/sdk from vulnerable versions (v1.21.0–v1.34.0) to v1.40.0 for virtualization-artifact, vm-route-forge, dvcr-artifact, virtualization-dra

Why do we need it, and what problem does it solve?

What is the expected result?

Checklist

  • The code is covered by unit tests.
  • e2e tests passed.
  • Documentation updated according to the changes.
  • Changes were tested in the Kubernetes cluster manually.

Changelog entries

section: core
type: fix
summary: fix CVE-2026-24051

Signed-off-by: Daniil Loktev <lokt.daniil@gmail.com>
loktev-d added 2 commits March 4, 2026 14:47
Signed-off-by: Daniil Loktev <lokt.daniil@gmail.com>
Signed-off-by: Daniil Loktev <lokt.daniil@gmail.com>
@loktev-d loktev-d added this to the v1.6.1 milestone Mar 4, 2026
Signed-off-by: Daniil Loktev <lokt.daniil@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant