—
GO-2026-5126
opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token in github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
Details
opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token in github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
Introduced in:
0 Fixed in: 0.154.0 Fix
go get github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter@v0.154.0