eBPF Instrumentation Vulnerability in OpenTelemetry by OpenTelemetry
CVE-2026-45679

6.5MEDIUM

Key Information:

Vendor
CVE Published:
2 June 2026

What is CVE-2026-45679?

The OpenTelemetry eBPF Instrumentation prior to version 0.9.0 is susceptible to a vulnerability that allows the export of raw Redis error messages, which may include attacker-controlled content or sensitive data. This can lead to unintentional exposure of tokens, personally identifiable information (PII), or other confidential data within telemetry backends. Attackers can exploit this vulnerability to inject untrusted text into downstream analysis systems, potentially compromising the integrity and confidentiality of the data being processed. The issue has been addressed in version 0.9.0 to mitigate these risks.

Affected Version(s)

opentelemetry-ebpf-instrumentation < 0.9.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.