
🚨 High - OpenTelemetry eBPF Instrumentation Denial of Service (CVE-2026-45678) An input validation vulnerability in the Postgres protocol parser of OpenTelemetry eBPF Instrumentation allows remote attackers to cause a Denial of Service (DoS). By sending an empty or truncated Postgres BIND payload lacking a expected NUL terminator, an attacker forces the instrumentation agent to slice beyond buffer boundaries, causing a runtime panic that halts telemetry collection. 👉 Affected: go.opentelemetry .io/obi (< 0.9.0) | Upgrade to 0.9.0
Post summary
CVE-2026-45678 is a high‑severity DoS flaw in OpenTelemetry eBPF Instrumentation triggered by malformed Postgres BIND payloads; upgrading to v0.9.0 resolves the issue.
