CVE-2026-45678Disclosure(opentelemetry / ebpf_instrumentation)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch opentelemetry ebpf_instrumentation systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic. This issue has been patched in version 0.9.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-754

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ebpf_instrumentation

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
ebpf_instrumentation

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-18: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-05-18: 105-18
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - OpenTelemetry eBPF Instrumentation Denial of Service (CVE-2026-45678) An input validation vulnerability in the Postgres protocol parser of OpenTelemetry eBPF Instrumentation allows remote attackers to cause a Denial of Service (DoS). By sending an empty or truncated Postgres BIND payload lacking a expected NUL terminator, an attacker forces the instrumentation agent to slice beyond buffer boundaries, causing a runtime panic that halts telemetry collection. 👉 Affected: go.opentelemetry .io/obi (< 0.9.0) | Upgrade to 0.9.0

    Post summary

    CVE-2026-45678 is a high‑severity DoS flaw in OpenTelemetry eBPF Instrumentation triggered by malformed Postgres BIND payloads; upgrading to v0.9.0 resolves the issue.

    0001195
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopentelemetryebpf_instrumentation-go-

Explore more