Upgrade opentelemetry-api to 1.62.0 due to CVE-2026-45292
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 65/100
Research direction
Start by locating the dependency declaration for opentelemetry-api in the pulsar-4.0 branch or module. Update it to 1.62.0 and run the relevant Pulsar build and dependency checks; the vulnerability report should no longer identify the older version.
Written by the indexing model from the issue text.
Description
Search before reporting
- I searched in the issues and found nothing similar.
Motivation
opentelemetry-api reporting for vulnerability CVE-2026-45292
https://nvd.nist.gov/vuln/detail/CVE-2026-45292
Solution
Upgrade opentelemetry to 1.62.0 in pulsar-4.0
Alternatives
No response
Anything else?
No response
Are you willing to submit a PR?
- I'm willing to submit a PR!
- Dominant language
- Java
- Stars
- 15.3k
- Forks
- 3.8k
- Avg merge
- 1d 45m
- Merged PRs (30d)
- 169
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/pulsar
-
area/function type/bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
type/bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
doc-required good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
type/bug
Difficulty 3/5 1-2 days Newbie friendliness 65/100
-
type/bug
Difficulty 3/5 1-2 days Newbie friendliness 58/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
infinispan/infinispan#18150 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
opensearch-project/k-NN#3597 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100