OpenTelemetry eBPF Instrumentation Vulnerability Affecting Multiple Systems
CVE-2026-45680
5.9MEDIUM
What is CVE-2026-45680?
The OpenTelemetry eBPF Instrumentation prior to version 0.9.0 contains a vulnerability that can impact the performance of busy systems. This occurs due to a loop that processes BPF probe hits into histogram observations, leading to excessive CPU usage when the run-count delta increases significantly. Such behavior can negatively affect system stability and performance during data collection intervals. The issue has been resolved in version 0.9.0, which optimizes the metrics export process.
Affected Version(s)
opentelemetry-ebpf-instrumentation < 0.9.0
