cvedb.io
CVE-2026-39883
HIGH · CVSS 7
EPSS exploitation probability: 0%
Published 2026-04-08T21:17:00.697 · Last modified 2026-06-30T03:19:07.957

Summary

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.

Affected products

opentelemetry — opentelemetry

Does this affect you?

Add your gear to cvedb and we'll alert you only when opentelemetry ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.