CVE-2026-45678
open-telemetry opentelemetry-ebpf-instrumentation, ebpf instrumentation 취약점
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic. This issue has been patched in version 0.9.0.
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 0.34% 백분위 26.8% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.03