-
-
Notifications
You must be signed in to change notification settings - Fork 0
chore(deps): GHSA-8988-4f7v-96qf in @opentelemetry/core (npm) #1751
Copy link
Copy link
Open
Labels
prio:mediumMedium priority.Medium priority.status:blockedWork cannot continue because of another issue, dependency, missing information, or decision.Work cannot continue because of another issue, dependency, missing information, or decision.type:dependenciesDependencies and upstream updates.Dependencies and upstream updates.
Description
Activity
Metadata
Metadata
Assignees
Labels
prio:mediumMedium priority.Medium priority.status:blockedWork cannot continue because of another issue, dependency, missing information, or decision.Work cannot continue because of another issue, dependency, missing information, or decision.type:dependenciesDependencies and upstream updates.Dependencies and upstream updates.
Package:
@opentelemetry/core@1.30.1Ecosystem: npm
Severity: moderate
Advisory: GHSA-8988-4f7v-96qf
Aliases: CVE-2026-54285
Summary: Unbounded memory allocation in W3C Baggage header parsing can lead to denial of service.
Dependency chain:
@sentry/astro@10.68.0 ->@sentry/node@10.68.0 ->@opentelemetry/sdk-trace-base@2.10.0 ->@opentelemetry/core@1.30.1 (also via@spotlightjs/astro)Why not auto-fixed: Fix requires a major upgrade of the OpenTelemetry SDK line, transitively controlled by
@sentry/astro/@spotlightjs/astro. Not a direct dependency we can override safely without risking Sentry/Spotlight instrumentation breakage.Closing with
resolution:wont-fix/resolution:invalidrecords this as an accepted risk on the next dependency scan. Closing withresolution:completedrecords it as fixed or worked around.