Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A race condition vulnerability exists in the OpenTelemetry-Go library versions 0.11.0 through 1.44.0. The issue arises from an unsynchronized map used in the OpenTracing bridge's bridgeSpan, which can cause concurrent access to trigger a runtime panic. This can lead to process termination and denial of service. The vulnerability is fixed in version 1.45.0. Join the discussion | CVE Database V5 | 08/24/2026, 21:19:00 UTC Added: 08/24/2026, 21:37:47 UTC |
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0. Join the discussion | CVE Database V5 | 04/08/2026, 20:26:41 UTC Added: 04/08/2026, 20:50:48 UTC |
0 CVE-2026-39882 is a medium severity vulnerability in the open-telemetry opentelemetry-go library versions prior to 1.43.0. The vulnerability arises because the OTLP HTTP exporters read the entire HTTP response body into memory without limiting its size, which can lead to memory exhaustion. This issue can be exploited if the collector endpoint is attacker-controlled or if a network attacker can intercept and manipulate the connection. The vulnerability has been fixed in version 1.43.0. Join the discussion | CVE Database V5 | 04/08/2026, 20:24:19 UTC Added: 04/08/2026, 20:50:48 UTC |
0 OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0. Join the discussion | CVE Database V5 | 04/07/2026, 20:29:13 UTC Added: 04/07/2026, 22:38:03 UTC |
CVE-2026-24051 is a high-severity vulnerability affecting the OpenTelemetry-Go SDK versions 1.21.0 up to but not including 1.40.0 on macOS/Darwin systems. The vulnerability arises from an untrusted search path (CWE-426) in the resource detection code that executes the 'ioreg' system command without specifying an absolute path. An attacker with local access who can modify the PATH environment variable can hijack this command execution to run arbitrary code within the application's context. This flaw allows for arbitrary code execution without user interaction but requires local privileges and a high attack complexity. No known exploits are currently reported in the wild. The issue was fixed in version 1. Join the discussion | CVE Database V5 | 02/02/2026, 19:49:10 UTC Added: 02/02/2026, 23:15:17 UTC |
Showing 1 to 5 of 5 results