Skip to content

v2.0.1 - CVE-2026-24051 Fix#122

Merged
jbarciabf merged 1 commit intoBishopFox:mainfrom
jbarciabf:fix/CVE-2026-24051
Mar 9, 2026
Merged

v2.0.1 - CVE-2026-24051 Fix#122
jbarciabf merged 1 commit intoBishopFox:mainfrom
jbarciabf:fix/CVE-2026-24051

Conversation

@jbarciabf
Copy link
Collaborator

Fixes PATH hijacking vulnerability in the OTel Go SDK on macOS/Darwin.

Card

Fix CVE-2026-24051: bump OTel SDK to v1.40.0

Details

Bumps go.opentelemetry.io/otel/sdk from v1.39.0 to v1.40.0 to fix CVE-2026-24051 (PATH hijacking on macOS/Darwin). No code changes, dependency-only update.

Fixes PATH hijacking vulnerability in the OTel Go SDK on macOS/Darwin.
@jbarciabf jbarciabf requested a review from bishopfaure as a code owner March 5, 2026 13:23
@jbarciabf jbarciabf added the dependencies Pull requests that update a dependency file label Mar 5, 2026
@jbarciabf jbarciabf requested a review from msperling-bf as a code owner March 5, 2026 13:23
@jbarciabf jbarciabf merged commit c6fcdba into BishopFox:main Mar 9, 2026
1 check passed
@jbarciabf jbarciabf deleted the fix/CVE-2026-24051 branch March 9, 2026 14:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants