CVE-2026-47256: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in open-telemetry opentelemetry-collector-contrib
OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter reads the remote OTLP sender-controlled service.name resource attribute in exporter/sentryexporter/sentry_exporter.go through extractProjectSlug and getOrCreateProjectEndpoint, passes the raw project slug to GetOTLPEndpoints and GetProjectKeys in exporter/sentryexporter/sentry_client.go, and interpolates it into a Sentry API URL without applying projectSlugRegexp through validateRoutingConfig at runtime in exporter/sentryexporter/config.go. Special characters can turn the expected path suffix into query data in all deployments or introduce slash and dot segments that traverse paths when the Sentry deployment normalizes them, while the Collector attaches its operator-configured bearer token to the request. A successful request can reach token-authorized administrative, organization, member, or key endpoints within the configured Sentry organization, and an attacker-controlled project slug can redirect subsequently exported telemetry. Sentry token middleware prevents cross-organization access. This issue is fixed in version 0.154.0.
AI Analysis
Technical Summary
OpenTelemetry Collector Contrib versions before 0.154.0 have a CWE-22 path traversal vulnerability in the Sentry exporter component. The Sentry exporter reads the remote OTLP sender-controlled service.name resource attribute as a project slug and interpolates it into a Sentry API URL without proper validation. This allows special characters to alter the URL path, potentially reaching token-authorized endpoints such as administrative, organization, member, or key endpoints within the same Sentry organization. The Sentry token middleware prevents cross-organization access. The vulnerability is resolved in version 0.154.0.
Potential Impact
An attacker controlling the project slug can exploit this vulnerability to access sensitive token-authorized endpoints within the configured Sentry organization, potentially redirecting exported telemetry data. The vulnerability does not allow cross-organization access due to token middleware restrictions. The CVSS score of 5.3 indicates a medium severity impact with low complexity and no user interaction required.
Mitigation Recommendations
Upgrade the OpenTelemetry Collector Contrib to version 0.154.0 or later, where this vulnerability is fixed. No other mitigations are indicated by the vendor advisory.
CVE-2026-47256: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in open-telemetry opentelemetry-collector-contrib
Description
OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter reads the remote OTLP sender-controlled service.name resource attribute in exporter/sentryexporter/sentry_exporter.go through extractProjectSlug and getOrCreateProjectEndpoint, passes the raw project slug to GetOTLPEndpoints and GetProjectKeys in exporter/sentryexporter/sentry_client.go, and interpolates it into a Sentry API URL without applying projectSlugRegexp through validateRoutingConfig at runtime in exporter/sentryexporter/config.go. Special characters can turn the expected path suffix into query data in all deployments or introduce slash and dot segments that traverse paths when the Sentry deployment normalizes them, while the Collector attaches its operator-configured bearer token to the request. A successful request can reach token-authorized administrative, organization, member, or key endpoints within the configured Sentry organization, and an attacker-controlled project slug can redirect subsequently exported telemetry. Sentry token middleware prevents cross-organization access. This issue is fixed in version 0.154.0.
CVSS v3.1
Score 5.3medium
Affected software
open-telemetry
opentelemetry-collector-contrib
open-telemetry
github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
pkg:github/open-telemetry/opentelemetry-collector-contribRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenTelemetry Collector Contrib versions before 0.154.0 have a CWE-22 path traversal vulnerability in the Sentry exporter component. The Sentry exporter reads the remote OTLP sender-controlled service.name resource attribute as a project slug and interpolates it into a Sentry API URL without proper validation. This allows special characters to alter the URL path, potentially reaching token-authorized endpoints such as administrative, organization, member, or key endpoints within the same Sentry organization. The Sentry token middleware prevents cross-organization access. The vulnerability is resolved in version 0.154.0.
Potential Impact
An attacker controlling the project slug can exploit this vulnerability to access sensitive token-authorized endpoints within the configured Sentry organization, potentially redirecting exported telemetry data. The vulnerability does not allow cross-organization access due to token middleware restrictions. The CVSS score of 5.3 indicates a medium severity impact with low complexity and no user interaction required.
Mitigation Recommendations
Upgrade the OpenTelemetry Collector Contrib to version 0.154.0 or later, where this vulnerability is fixed. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-18T23:03:37.228Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa8337755bf5e2cf5641819
Added to database: 09/14/2026, 17:48:39 UTC
Last enriched: 09/14/2026, 18:02:00 UTC
Last updated: 09/15/2026, 03:07:59 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.