OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.
References
| Link | Resource |
|---|---|
| http://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.43.0 | Release Notes |
| https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hfvc-g4fc-pqhx | Exploit Third Party Advisory |
Configurations
History
09 Apr 2026, 18:39
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.0 |
| CPE | cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:go:*:* | |
| References | () http://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.43.0 - Release Notes | |
| References | () https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hfvc-g4fc-pqhx - Exploit, Third Party Advisory | |
| First Time |
Opentelemetry opentelemetry
Opentelemetry |
08 Apr 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-08 21:17
Updated : 2026-04-10 21:16
NVD link : CVE-2026-39883
Mitre link : CVE-2026-39883
CVE.ORG link : CVE-2026-39883
JSON object : View
Products Affected
opentelemetry
- opentelemetry
CWE
CWE-426
Untrusted Search Path
