


Perceptive Security
SOC/SIEM Consultancy

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely rea…
Published:
1 juni 2026 om 22:00:00
Alert date:
2 juni 2026 om 17:02:02
Source:
nvd.nist.gov
Network Infrastructure, Security Tools
CVE-2026-45686 affects OpenTelemetry eBPF Instrumentation versions 0.7.0 to before 0.9.0. A remotely reachable integer overflow vulnerability exists in the memcached text protocol parser that can crash the OBI process and cause denial of service. The vulnerability occurs when parsing memcached storage commands with extremely large byte values, causing integer overflow and runtime panic. Attackers can exploit this by sending crafted requests with byte values set to math.MaxInt or math.MaxInt-1. The issue has been patched in version 0.9.0.
Technical details
Mitigation steps:
Affected products:
OpenTelemetry eBPF Instrumentation
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45686
https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/releases/tag/v0.9.0
https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/security/advisories/GHSA-43g7-cwr8-q3jh
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
