CVE-2026-24051
Vulnerability Summary
Timeline
Description
OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.
CVSS Metrics
- v3.1•HIGH•Score: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.16%• Percentile: 6%
Techniques & Countermeasures
- CWE-426•Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Affected Systems
- chainguard•agentbeat
< 0
- chainguard•agentbeat-fips
< 0
- chainguard•amazon-cloudwatch-agent
< 0
- chainguard•amazon-cloudwatch-agent-fips
< 0
- chainguard•ansible-operator
< 1.42.0-r9
- chainguard•ansible-operator-fips
< 1.42.0-r7
- chainguard•apisix-ingress-controller
< 0
- chainguard•apm-server-8.17
< 8.17.10-r6
- chainguard•apm-server-8.18
< 8.18.8-r5
- chainguard•apm-server-8.19
< 0
- chainguard•apm-server-9.0
< 9.0.8-r4
- chainguard•apm-server-9.1
< 9.1.10-r2
- chainguard•apm-server-9.2
< 9.2.5-r2
- chainguard•apm-server-9.3
< 9.3.0-r1
- chainguard•apm-server-fips-8.17
< 8.17.10-r5
- chainguard•apm-server-fips-8.18
< 8.18.8-r5
- chainguard•apm-server-fips-8.19
< 0
- chainguard•apm-server-fips-9.0
< 9.0.8-r5
- chainguard•apm-server-fips-9.1
< 9.1.10-r2
- chainguard•apm-server-fips-9.2
< 0
- chainguard•apm-server-fips-9.3
< 9.3.0-r1
- chainguard•argo-cd-2.14
all
- chainguard•argo-cd-2.14-compat
all
- chainguard•argo-cd-3.0
all
- chainguard•argo-cd-3.0-compat
all
- chainguard•argo-cd-3.1
< 0
- chainguard•argo-cd-3.1-compat
< 0
- chainguard•argo-cd-3.2
< 0
- chainguard•argo-cd-3.2-compat
< 0
- chainguard•argo-cd-3.3
< 0
- chainguard•argo-cd-3.3-compat
< 0
- chainguard•argo-cd-fips-2.14
all
- chainguard•argo-cd-fips-2.14-compat
all
- chainguard•argo-cd-fips-3.0
< 3.0.23-r9
- chainguard•argo-cd-fips-3.0-compat
< 3.0.23-r9
- chainguard•argo-cd-fips-3.1
< 3.1.12-r4
- chainguard•argo-cd-fips-3.1-compat
< 3.1.12-r4
- chainguard•argo-cd-fips-3.2
< 3.2.7-r2
- chainguard•argo-cd-fips-3.2-compat
< 3.2.7-r2
- chainguard•argo-cd-fips-3.3
< 3.3.2-r2
- chainguard•argo-cd-fips-3.3-compat
< 3.3.2-r2
- chainguard•argo-rollouts
< 0
- chainguard•argo-rollouts-fips
< 1.8.4-r3
- chainguard•argo-workflow-controller-3.6
< 0
- chainguard•argo-workflow-controller-3.7
< 0
- chainguard•argo-workflow-controller-4.0
< 4.0.1-r3
- chainguard•argo-workflow-controller-fips-3.6
< 0
- chainguard•argo-workflow-controller-fips-3.7
< 0
- chainguard•argo-workflow-controller-fips-4.0
< 4.0.1-r3
- chainguard•argo-workflow-executor-3.6
< 0
Showing first 50 affected entries in server-rendered view.
References (6)
- https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-9h8m-3fm2-qjrq
- https://github.com/open-telemetry/opentelemetry-go/commit/d45961bcda453fcbdb6469c22d6e88a1f9970a53
- https://github.com/open-telemetry/opentelemetry-go
- https://nvd.nist.gov/vuln/detail/CVE-2026-24051
- https://pkg.go.dev/vuln/GO-2026-4394
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24051.json