Skip to content

Bump OpenTelemetry package versions in ProjectTemplates.props to >= 1.15.3 (GHSA-g94r-2vxg-569j, GHSA-mr8r-92fq-pj8p, GHSA-q834-8qmm-v933) #7496

@ericstj

Description

@ericstj

Summary

The five OpenTelemetry packages pinned in eng/packages/ProjectTemplates.props are at version 1.14.0, which is vulnerable to three security advisories published April 23, 2026:

  • GHSA-g94r-2vxg-569j — Excessive memory allocation parsing OTel propagation headers (OpenTelemetry.Api, patched in 1.15.3)
  • GHSA-mr8r-92fq-pj8p — Unbounded grpc-status-details-bin parsing in OTLP/gRPC retry (OpenTelemetry.Exporter.OpenTelemetryProtocol, patched in 1.15.3)
  • GHSA-q834-8qmm-v933 — OTLP exporter reads unbounded HTTP response bodies (OpenTelemetry.Exporter.OpenTelemetryProtocol, patched in 1.15.2)

Proposed fix in eng/packages/ProjectTemplates.props:

<PackageVersion Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.15.3" />
<PackageVersion Include="OpenTelemetry.Extensions.Hosting"             Version="1.15.3" />
<PackageVersion Include="OpenTelemetry.Instrumentation.AspNetCore"     Version="1.15.3" />
<PackageVersion Include="OpenTelemetry.Instrumentation.Http"           Version="1.15.3" />
<PackageVersion Include="OpenTelemetry.Instrumentation.Runtime"       Version="1.15.3" />

This is a template-only version update; no shipped library APIs change.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area-telemetrybugThis issue describes a behavior which is not expected - a bug.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions