OpenTelemetry Java Agent: Unsafe Deserialization Vulnerability Reported
Versions prior to 2.26.1 of the OpenTelemetry Java agent reportedly have an unsafe deserialization vulnerability in RMI instrumentation that may lead to remote code execution under specific conditions.
What happened
An early warning has been issued regarding a potential unsafe deserialization vulnerability in versions prior to 2.26.1 of the OpenTelemetry Java agent. This vulnerability, tracked as GHSA-XW7X-H9FJ-P2C7, appears to be located in the RMI instrumentation component. It may lead to remote code execution if certain conditions are met, including network access to an RMI endpoint and the presence of a compatible library on the classpath.
Professional software engineers using the OpenTelemetry Java agent should assess their exposure by checking if they are running a version prior to 2.26.1. The recommended action is to upgrade to version 2.26.1 or later to mitigate the risk. The severity of this issue is currently classified as high.
For more detailed information, primary sources should be consulted. The GitHub Advisory Database entry (GHSA-xw7x-h9fj-p2c7) provides further insights into the vulnerability and its potential impact. As this is an early warning, the situation is under investigation, and details may evolve as more information becomes available.
How 0Day mitigates this
opentelemetry-javaagent is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.