DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-2ch2-4hh3-h64h

Package

grafana-alloy-fips

Component

go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc

Latest update

Fixed

Fixed version

1.20.0-r0

Aliases

Severity

Unknown
Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-81870

Updates

Status

Fixed

Fixed version

1.20.0-r0

Status

Pending upstream fix

Impact

The fix requires go.opentelemetry.io/otel/sdk v1.45.0, whose default resource uses semantic conventions schema 1.43.0. Grafana Alloy 1.19.2 hardcodes schema 1.41.0 in internal/runtime/tracing/tracing.go, and merging the two resources fails at startup, so the fixed module cannot be used without source changes. Upstream updated this in https://github.com/grafana/alloy/pull/7109, which is in v1.20.0-rc.0 but not yet in a stable release. We will ship the fix with the next Alloy release.

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.