MAVEN · MARCH 2026 · EARLY WARNING

OpenTelemetry Java Agent: Unsafe Deserialization Vulnerability Reported

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-XW7X-H9FJ-P2C7Severity: HIGH

Versions prior to 2.26.1 of the OpenTelemetry Java agent reportedly have an unsafe deserialization vulnerability in RMI instrumentation that may lead to remote code execution under specific conditions.

What happened

An early warning has been issued regarding a potential unsafe deserialization vulnerability in versions prior to 2.26.1 of the OpenTelemetry Java agent. This vulnerability, tracked as GHSA-XW7X-H9FJ-P2C7, appears to be located in the RMI instrumentation component. It may lead to remote code execution if certain conditions are met, including network access to an RMI endpoint and the presence of a compatible library on the classpath.

Professional software engineers using the OpenTelemetry Java agent should assess their exposure by checking if they are running a version prior to 2.26.1. The recommended action is to upgrade to version 2.26.1 or later to mitigate the risk. The severity of this issue is currently classified as high.

For more detailed information, primary sources should be consulted. The GitHub Advisory Database entry (GHSA-xw7x-h9fj-p2c7) provides further insights into the vulnerability and its potential impact. As this is an early warning, the situation is under investigation, and details may evolve as more information becomes available.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If opentelemetry-javaagent is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats