Upgrade opentelemetry to 1.62.0 due to CVE-2026-45292
- Dominant language
- Java
- Stars
- 2k
- Forks
- 976
- Avg merge
- 6d 15h
- Merged PRs (30d)
- 7
Description
**FEATURE REQUEST**
Pulsar 4.0 release is using Bookkeeper version 4.17.3 which has OTel integration
opentelemetry-api reporting for vulnerability [CVE-2026-45292](https://github.com/advisories/GHSA-rcgg-9c38-7xpx)
https://nvd.nist.gov/vuln/detail/CVE-2026-45292
Raised issue with Pulsar - https://github.com/apache/pulsar/issues/25903 and response was that "The OTel library upgrades most likely contains minor breaking changes which impact BookKeeper OTel integration so the BK release would have to happen first before upgrading."
The fix is available in opentelemetry 1.62.0 which needs to be incorporated with new Bookkeeper release version
Please make the necessary changes and share the timelines for Bookkeeper release which can be then incorporated in Apache Pulsar.
Contributor guide
Research direction
Start by reviewing BookKeeper 4.17.3's OpenTelemetry integration and the dependency change to opentelemetry 1.62.0. Check the compatibility concern raised in Pulsar issue 25903, then verify that the vulnerability is addressed without breaking the integration and determine the BookKeeper release needed for Pulsar to consume it.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- distributed-systems, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100