216.73.217.22

CVE-2026-39883

· Published 08/04/2026 21:17 · Modified 09/04/2026 18:39

Labels: CVE-2026-39883 2026-04-08CVE-2026-39883CWE-426[email protected]

Essential information

Published
08/04/2026 21:17
Modified
09/04/2026 18:39
Author
Creator
CVSS
7.3 HIGH (v3) 7.3 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.

NVD status

Status
Analyzed — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
opentelemetry / opentelemetry cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:go:*:*

References