eBPF Instrumentation Vulnerability in OpenTelemetry by OpenTelemetry
CVE-2026-45683

3.8LOW

Key Information:

Vendor
CVE Published:
2 June 2026

What is CVE-2026-45683?

The OpenTelemetry eBPF Instrumentation prior to version 0.9.0 is affected by a vulnerability where the Java TLS ioctl probe incorrectly handles user-controlled ioctl pointers. This misconfiguration allows an instrumented local process to direct OBI to access and copy sensitive kernel memory into telemetry data, potentially exposing sensitive information. This vulnerability has been addressed in version 0.9.0 with necessary patches.

Affected Version(s)

opentelemetry-ebpf-instrumentation < 0.9.0

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.