OpenTelemetry.AutoInstrumentation
OpenTelemetry Automatic Instrumentation package with all required components to enable automatic instrumentation.
Activity
- Latest release
- 2mo ago
- Total releases
- 26
- Cadence
- ~36 days
- Last 12 months
- 7
Details
- License
- Apache-2.0
- First release
- Jun 27, 2023
| Version | Released | |
|---|---|---|
1.16.0
minor
|
1.16.0
minor
Dependencies (6)
|
|
1.16.0-beta.1
pre
|
1.16.0-beta.1
pre
Dependencies (6)
|
|
1.15.0
minor
|
1.15.0
minor
Dependencies (6)
|
|
1.15.0-beta.1
pre
|
1.15.0-beta.1
pre
Dependencies (6)
|
|
1.14.1
patch
|
1.14.1
patch
Dependencies (6)
|
|
1.14.0
minor
|
1.14.0
minor
Dependencies (6)
|
|
1.13.0
minor
|
1.13.0
minor
Dependencies (6)
|
|
1.13.0-beta.1
pre
|
1.13.0-beta.1
pre
Dependencies (6)
|
|
1.12.0
minor
|
1.12.0
minor
Dependencies (6)
|
|
1.11.0
minor
|
1.11.0
minor
Dependencies (6)
|
|
1.10.0
minor
1 CVE
GHSA-vc29-vg52-6643
Mar 06, 2025
DoS Vulnerability in TraceContextPropagator.Extract - OpenTelemetry.Api
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability in Even if an application does not explicitly use trace context propagation, receiving these headers can still trigger high CPU usage. This issue impacts any application accessible over the web or backend services that process HTTP requests containing a tracestate header. Application may experience excessive resource consumption, leading to increased latency, degraded performance, or downtime. PatchesHas the problem been patched? What versions should users upgrade to? This issue has been resolved in Fixed version| OpenTelemetry .NET Automatic Instrumentation | Status | |----|----| | <= 1.9.0 | ✅ Not affected | | 1.10.0-beta.1, 1.10.0 | ❌ Vulnerable | | 1.11.0 (Fixed)| ✅ Safe to use| WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? ReferencesAre there any links users can visit to find out more? Affected versions
1.10.0
Fixed in
1.11.0
References
Updated Mar 06, 2025 · Source: OSV.dev |
1.10.0
minor
Dependencies (6)
|
|
1.10.0-beta.1
pre
1 CVE
GHSA-vc29-vg52-6643
Mar 06, 2025
DoS Vulnerability in TraceContextPropagator.Extract - OpenTelemetry.Api
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability in Even if an application does not explicitly use trace context propagation, receiving these headers can still trigger high CPU usage. This issue impacts any application accessible over the web or backend services that process HTTP requests containing a tracestate header. Application may experience excessive resource consumption, leading to increased latency, degraded performance, or downtime. PatchesHas the problem been patched? What versions should users upgrade to? This issue has been resolved in Fixed version| OpenTelemetry .NET Automatic Instrumentation | Status | |----|----| | <= 1.9.0 | ✅ Not affected | | 1.10.0-beta.1, 1.10.0 | ❌ Vulnerable | | 1.11.0 (Fixed)| ✅ Safe to use| WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? ReferencesAre there any links users can visit to find out more? Affected versions
1.10.0
Fixed in
1.11.0
References
Updated Mar 06, 2025 · Source: OSV.dev |
1.10.0-beta.1
pre
Dependencies (6)
|
|
1.9.0
minor
|
1.9.0
minor
Dependencies (6)
|
|
1.8.0
minor
|
1.8.0
minor
Dependencies (6)
|
|
1.7.0
minor
|
1.7.0
minor
Dependencies (6)
|
|
1.6.0
minor
|
1.6.0
minor
Dependencies (6)
|
|
1.5.0
minor
|
1.5.0
minor
Dependencies (6)
|
|
1.4.0
minor
|
1.4.0
minor
Dependencies (6)
|
|
1.3.0
minor
|
1.3.0
minor
Dependencies (6)
|
|
1.2.0
minor
|
1.2.0
minor
Dependencies (6)
|
|
1.1.0
minor
|
1.1.0
minor
Dependencies (6)
|
|
1.0.2
patch
|
1.0.2
patch
Dependencies (6)
|
|
1.0.1
patch
|
1.0.1
patch
Dependencies (6)
|
|
1.0.0
initial
|
1.0.0
initial
Dependencies (6)
|
|
1.0.0-rc.2
pre
|
1.0.0-rc.2
pre
Dependencies (6)
|
|
1.0.0-rc.1
pre
|
1.0.0-rc.1
pre
Dependencies (6)
|