eBPF Instrumentation Vulnerability in OpenTelemetry by OpenTelemetry
CVE-2026-45679
6.5MEDIUM
What is CVE-2026-45679?
The OpenTelemetry eBPF Instrumentation prior to version 0.9.0 is susceptible to a vulnerability that allows the export of raw Redis error messages, which may include attacker-controlled content or sensitive data. This can lead to unintentional exposure of tokens, personally identifiable information (PII), or other confidential data within telemetry backends. Attackers can exploit this vulnerability to inject untrusted text into downstream analysis systems, potentially compromising the integrity and confidentiality of the data being processed. The issue has been addressed in version 0.9.0 to mitigate these risks.
Affected Version(s)
opentelemetry-ebpf-instrumentation < 0.9.0
