GHSA-8rrq-wcg8-cv5q: OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
Summary
OpenTelemetry eBPF Instrumentation (OBI) exports unfiltered error messages from Redis directly into span status messages, which are then sent to telemetry backends (systems that collect and store trace data). This means sensitive information like tokens or passwords that appear in Redis errors could be leaked into monitoring systems, and attackers could inject malicious text into these systems.
Vulnerability Details
EPSS: 0.0%
Yes
May 18, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
GHSA-382c-vx95-w3p5: Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
CVE-2026-2589: The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure
Original source: https://github.com/advisories/GHSA-8rrq-wcg8-cv5q
First tracked: May 18, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 75%