Upgrade opentelemetry-api to 1.62.0 due to CVE-2026-45292

Open Beginner friendly
#25,903 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
65/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
java
Domain
security

Research direction

Start by locating the dependency declaration for opentelemetry-api in the pulsar-4.0 branch or module. Update it to 1.62.0 and run the relevant Pulsar build and dependency checks; the vulnerability report should no longer identify the older version.

Written by the indexing model from the issue text.

Description

type/enhancement
Search before reporting
  • I searched in the issues and found nothing similar.
Motivation

opentelemetry-api reporting for vulnerability CVE-2026-45292

https://nvd.nist.gov/vuln/detail/CVE-2026-45292

Solution

Upgrade opentelemetry to 1.62.0 in pulsar-4.0

Alternatives

No response

Anything else?

No response

Are you willing to submit a PR?
  • I'm willing to submit a PR!
Dominant language
Java
Stars
15.3k
Forks
3.8k
Avg merge
1d 45m
Merged PRs (30d)
169

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/pulsar

All issues in apache/pulsar

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.