Skip to content

chore(deps): GHSA-8988-4f7v-96qf in @opentelemetry/core (npm) #1751

Description

@davidsneighbour

Package: @opentelemetry/core@1.30.1
Ecosystem: npm
Severity: moderate
Advisory: GHSA-8988-4f7v-96qf
Aliases: CVE-2026-54285

Summary: Unbounded memory allocation in W3C Baggage header parsing can lead to denial of service.

Dependency chain: @sentry/astro@10.68.0 -> @sentry/node@10.68.0 -> @opentelemetry/sdk-trace-base@2.10.0 -> @opentelemetry/core@1.30.1 (also via @spotlightjs/astro)

Why not auto-fixed: Fix requires a major upgrade of the OpenTelemetry SDK line, transitively controlled by @sentry/astro/@spotlightjs/astro. Not a direct dependency we can override safely without risking Sentry/Spotlight instrumentation breakage.


Closing with resolution:wont-fix/resolution:invalid records this as an accepted risk on the next dependency scan. Closing with resolution:completed records it as fixed or worked around.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    prio:mediumMedium priority.status:blockedWork cannot continue because of another issue, dependency, missing information, or decision.type:dependenciesDependencies and upstream updates.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions