Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-24051

Опубликовано: 02 фев. 2026
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.

A flaw was found in OpenTelemetry-Go. On macOS/Darwin systems, the OpenTelemetry Go SDK is vulnerable to path hijacking, also known as untrusted search paths. A local attacker with the ability to modify the system's PATH environment variable could exploit this by injecting malicious code. This could lead to arbitrary code execution within the context of the application.

Отчет

Red Hat Workload Availability Operators FAR (fence-agents-remediation) and SBR (storage-based-remediation) bundle go.opentelemetry.io/otel/sdk in the vulnerable range (>=1.21.0, <1.40.0) prior to the rhwa-4.22-1 patch release. Fixed by bumping to v1.44.0 in the far-0.8.1 and sbr-0.3.1 streams. This flaw was previously auto-rejected (not found in Red Hat SBOM index at the time); reopened 2026-08-11 based on confirmed engineering source (dependency bump commits: FAR #211, SBR #80).

Меры по смягчению последствий

No customer action required for FAR/SBR as deployed on OpenShift: the vulnerable resource-detection code path only executes on macOS/Darwin hosts via the 'ioreg' command, which is never invoked on Red Hat's Linux container images. Fixed proactively via dependency bump to go.opentelemetry.io/otel/sdk v1.44.0 in far-0.8.1 and sbr-0.3.1.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fence Agents Remediation Operatorredhat-user-workloads/far-operator-0-8Affected
Storage-Based Remediationredhat-user-workloads/sbr-operator-0-3Affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-426
https://bugzilla.redhat.com/show_bug.cgi?id=2436129opentelemetry-go: OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking

EPSS

Процентиль: 5%
0.00157
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
6 месяцев назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.

CVSS3: 7
nvd
6 месяцев назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.

msrc
4 месяца назад

OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking

CVSS3: 7
debian
6 месяцев назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTe ...

CVSS3: 7
redos
около 2 месяцев назад

Уязвимость golang-opentelemetry-otel

EPSS

Процентиль: 5%
0.00157
Низкий

7 High

CVSS3