apache / apache/pulsar

Upgrade opentelemetry-api to 1.62.0 due to CVE-2026-45292

Open Beginner friendly
#25,903 3 comments 0 reactions 0 assignees View on GitHub
type/enhancement
Dominant language
Java
Stars
15.3k
Forks
3.8k
Avg merge
1d 14h
Merged PRs (30d)
160

Description

### Search before reporting

- [x] I searched in the [issues](https://github.com/apache/pulsar/issues) and found nothing similar.

### Motivation

opentelemetry-api reporting for vulnerability CVE-2026-45292

https://nvd.nist.gov/vuln/detail/CVE-2026-45292

### Solution

Upgrade opentelemetry to 1.62.0 in pulsar-4.0

### Alternatives

_No response_

### Anything else?

_No response_

### Are you willing to submit a PR?

- [ ] I'm willing to submit a PR!

Contributor guide

Open the contributing guide

Research direction

Start by locating the dependency declaration for opentelemetry-api in the pulsar-4.0 branch or module. Update it to 1.62.0 and run the relevant Pulsar build and dependency checks; the vulnerability report should no longer identify the older version.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
65/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.