Opentelemetry Opentelemetry/exporter-prometheus — known CVE vulnerabilities
Every CVE whose affected-product data names Opentelemetry Opentelemetry/exporter-prometheus, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (1)
CVE-2026-44902 — CVSS 7.5 (high): opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process…