CVE-2026-45679

Aliases:GHSA-8rrq-wcg8-cv5qGO-2026-5265
Advisory lineage Upstream: 0 Downstream: 2
Analyzed
Published: 02 Jun 2026, 15:24
Last modified:02 Jun 2026, 16:42

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.21% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

02 Jun 2026, 15:24
Published
Vulnerability first disclosed
02 Jun 2026, 16:42
Last Modified
Vulnerability information updated

Description

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-controlled or sensitive values, this behavior can exfiltrate tokens, PII, or other confidential input into telemetry backends and inject untrusted text into downstream analysis systems. This issue has been patched in version 0.9.0.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 0.21% Percentile: 12%

Techniques & Countermeasures

  • CWE-117Improper Output Neutralization for Logs

    The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

  • CWE-532Insertion of Sensitive Information into Log File

    The product writes sensitive information to a log file.

Affected Systems

  • go.opentelemetry.ioobi

    < 0.9.0

  • open-telemetryopentelemetry-ebpf-instrumentation

    < 0.9.0

  • opentelemetryebpf_instrumentation

    < 0.9.0

References (4)