GHSA-pgvv-q3wf-mm9m: OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
highvulnerability
OpenTelemetry eBPF Instrumentation (OBI) has a vulnerability in its Postgres protocol parser that can crash when it receives a malformed BIND message (a type of Postgres network packet). The parser doesn't check if the message payload is complete before reading from it, so an attacker could send a specially crafted empty or truncated packet to cause the program to panic and stop collecting telemetry data.
EPSS: 0.0%
Yes
May 18, 2026
Original source: https://github.com/advisories/GHSA-pgvv-q3wf-mm9m
First tracked: May 18, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%