Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8rrq-wcg8-cv5q | OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages |
Wed, 03 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opentelemetry ebpf Instrumentation
|
|
| CPEs | cpe:2.3:a:opentelemetry:ebpf_instrumentation:*:*:*:*:*:go:*:* | |
| Vendors & Products |
Opentelemetry ebpf Instrumentation
|
Tue, 02 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opentelemetry
Opentelemetry opentelemetry-ebpf-instrumentation |
|
| Vendors & Products |
Opentelemetry
Opentelemetry opentelemetry-ebpf-instrumentation |
Tue, 02 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-controlled or sensitive values, this behavior can exfiltrate tokens, PII, or other confidential input into telemetry backends and inject untrusted text into downstream analysis systems. This issue has been patched in version 0.9.0. | |
| Title | OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages | |
| Weaknesses | CWE-117 CWE-532 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T16:42:10.535Z
Reserved: 2026-05-12T21:59:25.667Z
Link: CVE-2026-45679
Updated: 2026-06-02T16:36:14.531Z
Status : Analyzed
Published: 2026-06-02T16:16:42.430
Modified: 2026-06-03T16:50:37.380
Link: CVE-2026-45679
No data.
OpenCVE Enrichment
Updated: 2026-06-02T17:00:16Z
Github GHSA