Path Hijacking Vulnerability in OpenTelemetry-Go by OpenTelemetry
CVE-2026-39883
7.3HIGH
What is CVE-2026-39883?
A vulnerability has been identified in OpenTelemetry-Go versions 1.15.0 to 1.42.0, where the BSD kenv command is susceptible to PATH hijacking. The fix for a related issue altered the Darwin ioreg command to utilize an absolute path, yet overlooked the BSD kenv command, which remains vulnerable. This flaw permits potential attackers to exploit environment variable manipulation on BSD and Solaris platforms. The vulnerability has been resolved in version 1.43.0, emphasizing the importance of updating to mitigate this security risk.
Affected Version(s)
opentelemetry-go >= 1.15.0, < 1.43.0
