VDB
KO

GO-2026-5126

opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token in github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter

Details

opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token in github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
Introduced in: 0 Fixed in: 0.154.0
Fix go get github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter@v0.154.0

References