Red Hat released Important security updates for opentelemetry-collector across multiple Red Hat Enterprise Linux 9 and 10 channels, including RHEL 9.4, 9.6, 10.0, and 10.2, along with SAP, EUS, Extended Life Cycle, and 4-year support streams. The updates ship opentelemetry-collector version 0.152.1 in platform-specific builds and affect x86_64, aarch64, ppc64le, and s390x systems.
The advisories remediate multiple bundled-component vulnerabilities in Prometheus, Apache Thrift, and Go libraries, including CVE-2026-42154, CVE-2026-42151, CVE-2026-43870, CVE-2026-33811, CVE-2026-39821, CVE-2026-27136, CVE-2026-25681, and CVE-2026-27145. Red Hat said the flaws could lead to denial of service, information disclosure including exposure of an Azure OAuth client secret, privilege escalation through Punycode label processing, cross-site scripting conditions in golang.org/x/net/html, and arbitrary code execution in affected deployments.

See real exploitation activity before you spend the cycle.
16 events from the most recent confirmed update back to the earliest known activity.
On August 11, 2026, Red Hat published RHSA-2026:53413, rated Important, for opentelemetry-collector on RHEL 10.0 Extended Update Support and related channels. The update released version 0.152.1-1.el10_0 and fixed multiple bundled-component vulnerabilities in Prometheus, Apache Thrift, and Go libraries.
On August 11, 2026, Red Hat published RHSA-2026:53415, an Important advisory for opentelemetry-collector across RHEL 9.6 support channels. The update provided version 0.152.1-1.el9_6 and addressed the same set of bundled-component flaws, including denial-of-service, information disclosure, privilege escalation, XSS, and arbitrary code execution issues.
On August 11, 2026, Red Hat published RHSA-2026:53412, rated Important, for opentelemetry-collector on RHEL 9.4 channels including SAP Solutions, AUS, 4-year updates, and Extended Life Cycle offerings. The update released version 0.152.1-1.el9_4 and remediated eight CVEs affecting Prometheus, Apache Thrift, and Go libraries.
On July 1, 2026, Red Hat published RHSA-2026:34359, an Important security advisory for opentelemetry-collector on RHEL 9.8 channels. The update shipped version 0.152.1-1.el9_8 and fixed six bundled-component vulnerabilities including CVE-2026-42154, CVE-2026-42151, CVE-2026-33811, CVE-2026-39821, CVE-2026-25681, and CVE-2026-27145.
On July 1, 2026, Red Hat published RHSA-2026:34357, an Important security advisory for opentelemetry-collector on RHEL 10.2 channels. The update shipped version 0.152.1-1.el10_2 and fixed bundled-component vulnerabilities including CVE-2026-42154, CVE-2026-42151, CVE-2026-33811, CVE-2026-39821, CVE-2026-25681, and CVE-2026-27145.
On May 20, 2026, Red Hat published RHSA-2026:19720, an Important security advisory for opentelemetry-collector on RHEL 9.6 channels including EUS and related service variants. The update shipped version 0.144.0-2.el9_6 and fixed eight bundled Go ecosystem vulnerabilities including CVE-2026-25679, CVE-2026-33186, CVE-2026-34986, CVE-2026-32281, CVE-2026-33810, CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
On May 20, 2026, Red Hat published RHSA-2026:19721, an Important security advisory for opentelemetry-collector on RHEL 9.4 channels including EUS, AUS, SAP, 4-year updates, and Extended Life Cycle variants. The update shipped version 0.144.0-2.el9_4 and fixed eight bundled Go ecosystem vulnerabilities including CVE-2026-25679, CVE-2026-33186, CVE-2026-34986, CVE-2026-32281, CVE-2026-33810, CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
On May 20, 2026, Red Hat published RHSA-2026:19719, an Important security advisory for opentelemetry-collector on Red Hat Enterprise Linux 10.0 Extended Update Support and 4-year update/support channels. The update shipped version 0.144.0-2.el10_0 and fixed eight bundled Go ecosystem vulnerabilities including CVE-2026-25679, CVE-2026-33186, CVE-2026-34986, CVE-2026-32281, CVE-2026-33810, CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
On May 19, 2026, Red Hat published RHSA-2026:19353, an Important security advisory for opentelemetry-collector on Red Hat Enterprise Linux 9 and related 9.8 support channels. The update shipped version 0.144.0-2.el9_8 and fixed eight bundled Go ecosystem vulnerabilities including CVE-2026-25679, CVE-2026-33186, CVE-2026-34986, CVE-2026-32281, CVE-2026-33810, CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
On May 19, 2026, Red Hat published RHSA-2026:19135, an Important security advisory for opentelemetry-collector on Red Hat Enterprise Linux 10 and related 10.2 support channels. The update shipped version 0.144.0-2.el10_2 and fixed eight bundled-component vulnerabilities including CVE-2026-25679, CVE-2026-33186, CVE-2026-34986, CVE-2026-32281, CVE-2026-33810, CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
Red Hat reported that CVE-2026-33810, a Go crypto/x509 certificate validation bypass involving excluded DNS constraints and differently cased wildcard DNS SANs, was addressed for Cryostat 4 on RHEL 9 in advisory RHSA-2026:14391. This adds a new affected product beyond the opentelemetry-collector RHEL advisories already in the timeline.
On March 11, 2026, Red Hat published RHSA-2026:4256, an Important security advisory for opentelemetry-collector on Red Hat Enterprise Linux 10.0 Extended Update Support and 4-year support channels. The update shipped version 0.144.0-1.el10_0 and fixed CVE-2025-61726 in Go's net/url and CVE-2025-68121 in crypto/tls.
On March 11, 2026, Red Hat published RHSA-2026:4267, an Important security advisory for opentelemetry-collector on RHEL 9.4 channels including EUS, AUS, SAP, 4-year updates, and Extended Life Cycle variants. The update shipped version 0.144.0-1.el9_4 and fixed CVE-2025-61726 in Go's net/url and CVE-2025-68121 in crypto/tls.
On March 11, 2026, Red Hat published RHSA-2026:4264, an Important security advisory for opentelemetry-collector on RHEL 9.6 channels. The update shipped version 0.144.0-1.el9_6 and fixed CVE-2025-61726 in Go's net/url and CVE-2025-68121 in crypto/tls.
On March 10, 2026, Red Hat published RHSA-2026:4174, an Important security advisory for opentelemetry-collector on Red Hat Enterprise Linux 10 channels. The update shipped version 0.144.0-1.el10_1 and fixed CVE-2025-61726 in Go's net/url and CVE-2025-68121 in crypto/tls.
On March 10, 2026, Red Hat published RHSA-2026:4177, an Important security advisory for opentelemetry-collector on Red Hat Enterprise Linux 9 channels. The update shipped version 0.144.0-1.el9_7 and fixed CVE-2025-61726 in Go's net/url and CVE-2025-68121 in crypto/tls.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
16 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.