VYPR

npm package

@opentelemetry/core

pkg:npm/%40opentelemetry/core

Vulnerabilities (1)

  • CVE-2026-54285Jun 15, 2026
    affected < 2.8.0fixed 2.8.0

    ## Overview `W3CBaggagePropagator.extract()` in `@opentelemetry/core` does not enforce size limits when parsing inbound `baggage` HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and 180 entries; these limits were only enforced on the outbound (`in