opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay in github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
{
"url": "https://pkg.go.dev/vuln/GO-2026-5544",
"review_status": "UNREVIEWED"
}