Junglewise Threat Intelligence

CVE-2026-45678: OpenTelemetry OBI denial of service in Postgres protocol parser

CVE-2026-45678 · Severity: high · CVSS 7.5 · Published 2026-06-02

Technologies: go.opentelemetry.io/obi (Go), Opentelemetry eBPF Instrumentation. Vendors: Opentelemetry, Go.

Executive brief

OpenTelemetry eBPF Instrumentation is a tool used to monitor application performance and database traffic without modifying application code. A vulnerability in its PostgreSQL protocol parser allows a remote attacker to crash the monitoring agent by sending specially crafted database messages. This results in a denial of service for the telemetry system, causing a loss of visibility into the monitored environment.

Technical details

A vulnerability exists in the Postgres protocol parser within OpenTelemetry eBPF Instrumentation (OBI) prior to version 0.9.0. The parser in 'pkg/ebpf/common/sql_detect_postgres.go' incorrectly assumes that BIND message payloads contain a valid NUL-terminated portal name. When processing a crafted empty or unterminated payload, the code attempts to slice the message buffer beyond its actual length after calling 'unix.ByteSliceToString'. This results in a Go runtime panic (index out of range). An unauthenticated remote attacker sending malformed Postgres traffic to a monitored service can crash the OBI agent, terminating telemetry collection. The issue is fixed in version 0.9.0.

Affected products

  • OpenTelemetry OpenTelemetry eBPF Instrumentation (OBI) < 0.9.0

Timeline

  • 2026-05-11: patched: Version 0.9.0 released
  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-06-02: disclosed: CVE published to NVD

References

Related threats