CVE-2026-45678

HIGH

OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads

Title source: cna
STIX 2.1

Description

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic. This issue has been patched in version 0.9.0.

Scores

CVSS v3 7.5
EPSS 0.0029
EPSS Percentile 20.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-20 CWE-754
Status published
Products (3)
go.opentelemetry.io/obi 0 - 0.9.0Go
open-telemetry/opentelemetry-ebpf-instrumentation < 0.9.0
opentelemetry/ebpf_instrumentation < 0.9.0
Published Jun 02, 2026
Tracked Since Jun 02, 2026