Skip to content

BAU: Constrain opentelemetry-api to 1.62.0 to fix CVE-2026-45292#8347

Open
alhcomer wants to merge 1 commit into
mainfrom
BAU/constrain-opentelemetry-api-to-1.62.0
Open

BAU: Constrain opentelemetry-api to 1.62.0 to fix CVE-2026-45292#8347
alhcomer wants to merge 1 commit into
mainfrom
BAU/constrain-opentelemetry-api-to-1.62.0

Conversation

@alhcomer
Copy link
Copy Markdown
Contributor

What

  • Constrains io.opentelemetry:opentelemetry-api to >=1.62.0 to fix CVE-2026-45292 (unbounded memory allocation in W3C Baggage propagation). This is a transitive dependency brought in via the AWS SDK BOM.

How to review

  1. Code Review

- CVE-2026-45292: unbounded memory allocation in W3C Baggage
  propagation. Constraining to >=1.62.0 where the fix was
  released. This is a transitive dependency brought in via
  the AWS SDK BOM.

See: https://github.com/govuk-one-login/authentication-api/security/dependabot/116
@alhcomer alhcomer requested review from a team as code owners May 18, 2026 14:25
@sonarqubecloud
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants