Upgrade opentelemetry-api to 1.62.0 due to CVE-2026-45292
- Dominant language
- Java
- Stars
- 15.3k
- Forks
- 3.8k
- Avg merge
- 1d 14h
- Merged PRs (30d)
- 160
Description
### Search before reporting
- [x] I searched in the [issues](https://github.com/apache/pulsar/issues) and found nothing similar.
### Motivation
opentelemetry-api reporting for vulnerability CVE-2026-45292
https://nvd.nist.gov/vuln/detail/CVE-2026-45292
### Solution
Upgrade opentelemetry to 1.62.0 in pulsar-4.0
### Alternatives
_No response_
### Anything else?
_No response_
### Are you willing to submit a PR?
- [ ] I'm willing to submit a PR!
Contributor guide
Research direction
Start by locating the dependency declaration for opentelemetry-api in the pulsar-4.0 branch or module. Update it to 1.62.0 and run the relevant Pulsar build and dependency checks; the vulnerability report should no longer identify the older version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 65/100