Path Hijacking Vulnerability in OpenTelemetry-Go by OpenTelemetry
CVE-2026-39883

7.3HIGH

Key Information:

Vendor
CVE Published:
8 April 2026

What is CVE-2026-39883?

A vulnerability has been identified in OpenTelemetry-Go versions 1.15.0 to 1.42.0, where the BSD kenv command is susceptible to PATH hijacking. The fix for a related issue altered the Darwin ioreg command to utilize an absolute path, yet overlooked the BSD kenv command, which remains vulnerable. This flaw permits potential attackers to exploit environment variable manipulation on BSD and Solaris platforms. The vulnerability has been resolved in version 1.43.0, emphasizing the importance of updating to mitigate this security risk.

Affected Version(s)

opentelemetry-go >= 1.15.0, < 1.43.0

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.