CVE-2026-24051Patch(opentelemetry / opentelemetry)

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch opentelemetry opentelemetry systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opentelemetry

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 7 mentions (2026-03-11); latest day: 1
  • 12 total mentions across 5 days

Affected systems

Products
opentelemetry

Deep dive

Activity timeline12 mentions / 5d
02457Mentions · 2026-02-03: 2Mentions · 2026-03-11: 7Mentions · 2026-04-09: 1Mentions · 2026-06-15: 1Mentions · 2026-07-20: 1Patch / Workaround · 2026-03-11: 7Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-07-20: 1Technical Details · 2026-02-03: 2Technical Details · 2026-06-15: 1Technical Details · 2026-07-20: 102-0303-1104-0906-1507-20
Signal classification3 categories
Patch
975.0%
Disclosure
216.7%
General
18.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-032
Disclosure2
2026-03-117
Patch7
2026-04-091
General1
2026-06-151
Patch1
2026-07-201
Patch1
Full discourse12 posts
  • Altinity@AltinityDB
    Patch

    If a Keeper node ever went quiet after a config change, check out the Altinity #Kubernetes Operator for #ClickHouse® 0.26.2 - Keeper offline, race condition, & namespace handling fixes, CVE-2026-24051 patched, and faster multi-node CHI/CHK deletion. 🛡️ https://hubs.la/Q04ln0nR0 https://t.co/9ftYb8wnfy

    Post summary

    The tweet announces that the Altinity Kubernetes Operator version 0.26.2 patches CVE-2026-24051, fixing a race condition and namespace handling issues for ClickHouse.

    00001161
    1.7K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 N/A Security fixes for apigee-redis 17/19

    Post summary

    The text announces that security fixes for apigee‑redis 17/19 address a list of CVEs.

    1000091
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-47913 CVE-2025-4674 N/A Security fixes for apigee-prometheus-adapter 16/19

    Post summary

    The message enumerates several CVEs and notes that security fixes exist for apigee-prometheus-adapter, indicating patch availability without specifying exploit details.

    1000097
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68156 CVE-2025-61729 CVE-2025-4674 CVE-2025-29786 N/A Security fixes for apigee-open-telemetry-collector: 14/19

    Post summary

    The post lists several CVE identifiers and announces that security fixes are available for the Apigee Open Telemetry Collector, indicating a patch release.

    1000085
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    CVE-2025-47907 CVE-2025-4674 N/A Security fixes for apigee-kube-rbac-proxy. This addresses the following vulnerabilities: CVE-2025-61729 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 N/A Security fixes for apigee-open-telemetry-collector 13/19

    Post summary

    The text reports that security fixes have been applied to the apigee-kube-rbac-proxy and apigee-open-telemetry-collector for several CVEs, providing patch information but no technical or exploitation details.

    1000085
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 12/19

    Post summary

    The snippet announces security fixes for apigee-hybrid-cassandra-client that address multiple CVEs, indicating that patches are available.

    1000081
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-asm-ingress. This addresses the following vulnerability: CVE-2026-24051 N/A Security fixes for apigee-connect-agent. This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 11/19

    Post summary

    The post announces that security fixes are now available for several CVEs affecting Apigee components, marking it as a patch release announcement.

    1000097
    1.8K followersView on X
  • VulniPulse@vulnipulse
    Patch

    ⚠️ NetApp Console Agent alert: CVE-2026-24051 (CVSS 7.0) Attackers could disrupt service or cause a denial of service. No workaround; upgrade to a vendor-listed fixed release. https://vulnipulse.com/advisories/netapp-ntap-20260612-0010 #NetApp #NetAppConsoleAgent #CyberSecurity #CVE

    Post summary

    The advisory announces CVE‑2026‑24051, highlights denial‑of‑service risk, and directs users to upgrade to the vendor‑fixed release.

    0000037
    6 followersView on X
  • DailyCVE@dailycve
    General

    🔴 OpenTelemetry Go SDK, Path Hijacking, #CVE-2026-24051 (Critical) https://dailycve.com/opentelemetry-go-sdk-path-hijacking-cve-2026-24051-critical/

    Post summary

    The post provides only a headline and link about a critical Path Hijacking vulnerability in the OpenTelemetry Go SDK, offering minimal detail and no evidence of exploitation or mitigation.

    0000032
    178 followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-stackdriver-logging-agent. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907. 19/19

    Post summary

    The statement lists a series of CVEs that the apigee-stackdriver-logging-agent claims to fix, indicating a patch release without any evidence of exploitation or detailed vulnerability information.

    00000116
    1.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24051 OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths… https://www.cve.org/CVERecord?id=CVE-2026-24051

    Post summary

    CVE-2026-24051 discloses a Path Hijacking vulnerability in OpenTelemetry-Go SDK versions v1.20.0 to v1.39.0, with no mention of exploits, patches, or active attacks.

    00000195
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24051 OpenTelemetry-Go SDK Path Hijacking Vulnerability on macOS/Darwin Systems https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24051

    Post summary

    The text announces a new path hijacking vulnerability in OpenTelemetry-Go SDK on macOS/Darwin systems, but provides no proof of concept, exploit, or mitigation details.

    0000050
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopentelemetryopentelemetry-go-

Explore more