OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-controlled or sensitive values, this behavior can exfiltrate tokens, PII, or other confidential input into telemetry backends and inject untrusted text into downstream analysis systems. This issue has been patched in version 0.9.0.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opentelemetry
Opentelemetry opentelemetry-ebpf-instrumentation |
|
| Vendors & Products |
Opentelemetry
Opentelemetry opentelemetry-ebpf-instrumentation |
Tue, 02 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-controlled or sensitive values, this behavior can exfiltrate tokens, PII, or other confidential input into telemetry backends and inject untrusted text into downstream analysis systems. This issue has been patched in version 0.9.0. | |
| Title | OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages | |
| Weaknesses | CWE-117 CWE-532 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T16:42:10.535Z
Reserved: 2026-05-12T21:59:25.667Z
Link: CVE-2026-45679
Updated: 2026-06-02T16:36:14.531Z
Status : Undergoing Analysis
Published: 2026-06-02T16:16:42.430
Modified: 2026-06-02T17:16:34.363
Link: CVE-2026-45679
No data.
OpenCVE Enrichment
Updated: 2026-06-02T17:00:16Z