eBPF String Injection Vulnerability in Inspektor Gadget Tools by Inspektor Gadget
CVE-2026-25996

6.9MEDIUM

Key Information:

Vendor
CVE Published:
12 February 2026

What is CVE-2026-25996?

The Inspektor Gadget tools, designed for data collection and system inspection on Kubernetes clusters and Linux hosts leveraging eBPF, expose a vulnerability where string fields from eBPF events are outputted to the terminal without proper sanitization. This lack of sanitization allows malicious payloads to introduce control characters and ANSI escape sequences, which could manipulate the display for operators who interact with the terminal, potentially leading to information disclosure or operational disruptions.

Affected Version(s)

inspektor-gadget < 0.49.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.