CVE-2026-41178: go.opentelemetry.io/otel/baggage,go.opentelemetry.io/otel/propagation: no rejection of raw-length
headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510).
CVE-2026-63308: processing zero-length byte slices in template chart files can trigger an index out-of-range panic
(bsc#1272402).
gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation
(bsc#1276514).