CVE-2026-45682

MEDIUM

OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals

Title source: cna
STIX 2.1

Description

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In long-running instrumented JVMs, repeated connection churn can therefore grow the queue without bound and exhaust heap memory. This issue has been patched in version 0.9.0.

Scores

CVSS v3 5.1
EPSS 0.0012
EPSS Percentile 2.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-401 CWE-770
Status published
Products (3)
go.opentelemetry.io/obi 0 - 0.9.0Go
open-telemetry/opentelemetry-ebpf-instrumentation < 0.9.0
opentelemetry/ebpf_instrumentation < 0.9.0
Published Jun 02, 2026
Tracked Since Jun 02, 2026