CVE-2026-45682
CVE-2026-45682 is a medium-severity vulnerability in Opentelemetry Ebpf Instrumentation with a CVSS 3.x base score of 5.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-401.
Key facts
- Severity: Medium (CVSS 3.x base score 5.1)
- EPSS exploit prediction: 0% (6th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-33950
- Weakness: CWE-401
- Affected product: Opentelemetry Ebpf Instrumentation
- Published:
- Last modified:
Description
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In long-running instrumented JVMs, repeated connection churn can therefore grow the queue without bound and exhaust heap memory. This issue has been patched in version 0.9.0.
Frequently asked questions
- What is CVE-2026-45682?
- OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In long-running instrumented JVMs, repeated connection churn can therefore grow the queue without bound and exhaust heap memory. This issue has been patched in version 0.9.0.
- How severe is CVE-2026-45682?
- CVE-2026-45682 has a CVSS 3.x base score of 5.1, rated medium severity. It is exploitable over local access with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2026-45682 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (6th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-45682?
- CVE-2026-45682 affects Opentelemetry Ebpf Instrumentation. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-45682?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-45682 have an EU (EUVD) identifier?
- Yes. CVE-2026-45682 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-33950.
- When was CVE-2026-45682 published?
- CVE-2026-45682 was published on 2026-06-02 and last updated on 2026-07-22.
References
- https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/releases/tag/v0.9.0
- https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/security/advisories/GHSA-962q-hwm5-52x5
Affected products (1)
- cpe:2.3:a:opentelemetry:ebpf_instrumentation:*:*:*:*:*:go:*:*
More vulnerabilities in Opentelemetry Ebpf Instrumentation
- CVE-2026-45686 — High (CVSS 7.5): OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version…
- CVE-2026-45685 — High (CVSS 7.5): OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version…
- CVE-2026-45678 — High (CVSS 7.5): OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version…
- CVE-2026-45679 — Medium (CVSS 6.5): OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version…
- CVE-2026-45681 — Medium (CVSS 5.9): OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version…
- CVE-2026-45680 — Medium (CVSS 5.9): OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version…
All CVEs affecting Opentelemetry Ebpf Instrumentation →
Other CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities
- CVE-2026-46289 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in…
- CVE-2025-39948 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: ice: fix Rx page leak on multi-buffer frames The…
- CVE-2025-21954 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently…
- CVE-2024-57947 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map…
- CVE-2024-56779 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfs4_openowner leak when concurrent…
- CVE-2024-36911 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo…
Browse all CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities →