eBPF Instrumentation Vulnerability in OpenTelemetry by OpenTelemetry
CVE-2026-45683
3.8LOW
What is CVE-2026-45683?
The OpenTelemetry eBPF Instrumentation prior to version 0.9.0 is affected by a vulnerability where the Java TLS ioctl probe incorrectly handles user-controlled ioctl pointers. This misconfiguration allows an instrumented local process to direct OBI to access and copy sensitive kernel memory into telemetry data, potentially exposing sensitive information. This vulnerability has been addressed in version 0.9.0 with necessary patches.
Affected Version(s)
opentelemetry-ebpf-instrumentation < 0.9.0
