Denial of Service Vulnerability in OpenTelemetry eBPF Profiler by OpenTelemetry
CVE-2026-48496

6.2MEDIUM

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-48496?

The OpenTelemetry eBPF Profiler, designed for application profiling across various programming languages, is susceptible to a denial of service attack. An unprivileged process can exploit this vulnerability by causing the profiler to access a nonregular mapping file, such as a FIFO. When this occurs, the profiler may end up in a blocking state indefinitely, thus halting any further ELF analysis. This can disrupt normal operations and degrade application performance. A fix has been implemented in version 0.0.202622, and no workarounds exist for earlier versions.

Affected Version(s)

opentelemetry-ebpf-profiler >= 0.0.202527, < 0.0.202622

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.