ZeroHour

CVE-2026-45678

PoC
CVSS 3.1
7.5 high
EPSS
<1%p27
Published
()
Modified
Description

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic. This issue has been patched in version 0.9.0.

Vendors
opentelemetry
Products
ebpf instrumentation
Weakness
CWE-20, CWE-754
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.