GHSA-8wmf-6v46-5gfg: OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Summary
OpenTelemetry-Go versions 1.5.0 through 1.44.0 can accidentally leak trace exporter endpoint URLs and configuration details in internal diagnostic logs when an application enables verbose logging. The vulnerability only affects apps that explicitly configure a verbose logger and use exporters like Zipkin with credentials embedded in URLs, potentially exposing collector addresses, network topology, and embedded credentials to anyone with access to those logs.
Solution / Mitigation
Update to OpenTelemetry-Go version 1.45.0 or later. The source text indicates the vulnerability affects versions 1.5.0 through 1.44.0, implying a fix is available in subsequent releases.
Vulnerability Details
EPSS: 0.0%
Yes
September 17, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-8wmf-6v46-5gfg
First tracked: September 17, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 65%