OpenTelemetry eBPF Instrumentation是OpenTelemetry开源的一个基于eBPF的轻量级遥测数据采集工具。 OpenTelemetry eBPF Instrumentation 0.9.0之前版本存在安全漏洞,该漏洞源于导出原始Redis错误文本作为跨度状态消息,可能导致泄露令牌、PII或其他机密输入到遥测后端。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| open-telemetry | opentelemetry-ebpf-instrumentation | < 0.9.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| open-telemetry | opentelemetry-ebpf-instrumentation | < 0.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45685 | 7.5 HIGH | OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages |
| CVE-2026-45686 | 7.5 HIGH | OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI |
| CVE-2026-45678 | 7.5 HIGH | OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads |
| CVE-2026-45681 | 5.9 MEDIUM | OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB si |
| CVE-2026-45680 | 5.9 MEDIUM | OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU |
| CVE-2026-45676 | 5.5 MEDIUM | OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash a |
| CVE-2026-45682 | 5.1 MEDIUM | OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals |
| CVE-2026-45684 | 4.9 MEDIUM | OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite us |
| CVE-2026-45683 | 3.8 LOW | OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure |
No comments yet