apache / apache/bookkeeper

Upgrade opentelemetry to 1.62.0 due to CVE-2026-45292

Open
#4,809 0 comments 0 reactions 0 assignees View on GitHub
type/feature
Dominant language
Java
Stars
2k
Forks
976
Avg merge
6d 15h
Merged PRs (30d)
7

Description

**FEATURE REQUEST**
Pulsar 4.0 release is using Bookkeeper version 4.17.3 which has OTel integration

opentelemetry-api reporting for vulnerability [CVE-2026-45292](https://github.com/advisories/GHSA-rcgg-9c38-7xpx)

https://nvd.nist.gov/vuln/detail/CVE-2026-45292

Raised issue with Pulsar - https://github.com/apache/pulsar/issues/25903 and response was that "The OTel library upgrades most likely contains minor breaking changes which impact BookKeeper OTel integration so the BK release would have to happen first before upgrading."

The fix is available in opentelemetry 1.62.0 which needs to be incorporated with new Bookkeeper release version

Please make the necessary changes and share the timelines for Bookkeeper release which can be then incorporated in Apache Pulsar.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing BookKeeper 4.17.3's OpenTelemetry integration and the dependency change to opentelemetry 1.62.0. Check the compatibility concern raised in Pulsar issue 25903, then verify that the vulnerability is addressed without breaking the integration and determine the BookKeeper release needed for Pulsar to consume it.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
distributed-systems, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.