Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

opentelemetry-ebpf-instrumentation — Vulnerabilities & Security Advisories 11

All 11 CVE vulnerabilities found in opentelemetry-ebpf-instrumentation, with AI-generated Chinese analysis, references, and POCs.

Vendor: open-telemetry

CVE IDTitleCVSSSeverityPublished
CVE-2026-45686 OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI CWE-190 7.5 High2026-06-02
CVE-2026-45685 OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages CWE-20 7.5 High2026-06-02
CVE-2026-45684 OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers CWE-126 4.9 Medium2026-06-02
CVE-2026-45683 OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure CWE-127 3.8 Low2026-06-02
CVE-2026-45681 OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size CWE-125 5.9 Medium2026-06-02
CVE-2026-45680 OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU CWE-400 5.9 Medium2026-06-02
CVE-2026-45679 OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages CWE-117 6.5 Medium2026-06-02
CVE-2026-45678 OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads CWE-20 7.5 High2026-06-02
CVE-2026-45676 OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent CWE-20 5.5 Medium2026-06-02
CVE-2026-45682 OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals CWE-401 5.1 Medium2026-06-02
CVE-2026-41433 OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIR CWE-22 8.4 High2026-04-24

All 11 known CVE vulnerabilities affecting opentelemetry-ebpf-instrumentation with full Chinese analysis, references, and POCs where available.