CVE Database
/

CVE-2026-39883

Back to search

CVE-2026-39883

Published: Apr 8, 2026

Modified: Apr 10, 2026

PUBLISHED

Description

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.

VendorProductVersions

open-telemetry

opentelemetry-go

affected
>= 1.15.0, < 1.43.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now