Executive brief
OpenTelemetry eBPF Instrumentation is a tool used to monitor application performance and database traffic without modifying application code. A vulnerability in its PostgreSQL protocol parser allows a remote attacker to crash the monitoring agent by sending specially crafted database messages. This results in a denial of service for the telemetry system, causing a loss of visibility into the monitored environment.
Technical details
A vulnerability exists in the Postgres protocol parser within OpenTelemetry eBPF Instrumentation (OBI) prior to version 0.9.0. The parser in 'pkg/ebpf/common/sql_detect_postgres.go' incorrectly assumes that BIND message payloads contain a valid NUL-terminated portal name. When processing a crafted empty or unterminated payload, the code attempts to slice the message buffer beyond its actual length after calling 'unix.ByteSliceToString'. This results in a Go runtime panic (index out of range). An unauthenticated remote attacker sending malformed Postgres traffic to a monitored service can crash the OBI agent, terminating telemetry collection. The issue is fixed in version 0.9.0.
Affected products
- OpenTelemetry OpenTelemetry eBPF Instrumentation (OBI) < 0.9.0
Timeline
- 2026-05-11: patched: Version 0.9.0 released
- 2026-05-12: advisory: GitHub Security Advisory published
- 2026-06-02: disclosed: CVE published to NVD