npm vulnerability intelligence

@opentelemetry/core NPM Package
Vulnerability Check

OpenTelemetry Core provides constants and utilities shared by all OpenTelemetry SDK packages.

Moderate Apache-2.0 v2.10.0
Vulnerability Analysis OSV Live

@opentelemetry/core

v2.10.0 · Apache-2.0

Advisory Breakdown

Critical 0
High 0
Moderate 1
Low 0

Severity Rating

Moderate

1 advisory

Moderate

Weekly downloads

Total advisories

1

Latest version

2.10.0

License

Apache-2.0

Known advisories

OSV records for the npm ecosystem

1
GHSA-8988-4f7v-96qf CVE-2026-54285 moderate

OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation

Affected: >=0 <2.8.0 Fixed in: 2.8.0 Updated Jun 19, 2026
View source

Checked Aug 12, 2026, 7:44 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
@opentelemetry/core
Ecosystem
npm
Latest version
2.10.0
License
Apache-2.0
Weekly downloads
Unavailable

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 8/12/2026, 7:44:55 PM