Package URl
pkg:maven/io.opentelemetry/opentelemetry-.*@1.62.0
CPE
cpe:2.3:a:opentelemetry:opentelemetry:1.62.0:::::::*
CVE
No response
ODC Integration
{"label" => "Gradle Plugin"}
ODC Version
13.0.0
Description
I am seeing CVE-2026-54285 with a CPE specifically for node.js which concerns something about the opentelemetry-js client being reported against 14 individual package URIs which are all JARs. Not sure if this can be solved at once or whether I'm really supposed to open 14 FP reports? I can say we already have the retirejs analyzer disabled.
Package URl
pkg:maven/io.opentelemetry/opentelemetry-.*@1.62.0
CPE
cpe:2.3:a:opentelemetry:opentelemetry:1.62.0:::::::*
CVE
No response
ODC Integration
{"label" => "Gradle Plugin"}
ODC Version
13.0.0
Description
I am seeing CVE-2026-54285 with a CPE specifically for node.js which concerns something about the opentelemetry-js client being reported against 14 individual package URIs which are all JARs. Not sure if this can be solved at once or whether I'm really supposed to open 14 FP reports? I can say we already have the retirejs analyzer disabled.