GHSA-8rrq-wcg8-cv5q: OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
Summary
OpenTelemetry eBPF Instrumentation (OBI) exports unfiltered error messages from Redis directly into span status messages, which are then sent to telemetry backends (systems that collect and store trace data). This means sensitive information like tokens or passwords that appear in Redis errors could be leaked into monitoring systems, and attackers could inject malicious text into these systems.
Vulnerability Details
EPSS: 0.0%
Yes
May 18, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-8rrq-wcg8-cv5q
First tracked: May 18, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 75%