Denial of Service Vulnerability in OpenTelemetry eBPF Profiler by OpenTelemetry
CVE-2026-48496
6.2MEDIUM
What is CVE-2026-48496?
The OpenTelemetry eBPF Profiler, designed for application profiling across various programming languages, is susceptible to a denial of service attack. An unprivileged process can exploit this vulnerability by causing the profiler to access a nonregular mapping file, such as a FIFO. When this occurs, the profiler may end up in a blocking state indefinitely, thus halting any further ELF analysis. This can disrupt normal operations and degrade application performance. A fix has been implemented in version 0.0.202622, and no workarounds exist for earlier versions.
Affected Version(s)
opentelemetry-ebpf-profiler >= 0.0.202527, < 0.0.202622
