{"id":"CVE-2026-48496","title":"OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages","summary":"OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to o…","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-770"],"vendor":"open-telemetry","product":"opentelemetry-ebpf-profiler","affected":["opentelemetry-ebpf-profiler >= 0.0.202527, < 0.0.202622"],"patched":["go.opentelemetry.io/ebpf-profiler 0.0.202622"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T20:16:44.240","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48496","references":[{"url":"https://github.com/open-telemetry/opentelemetry-ebpf-profiler/commit/234b685cab31c2cb2f79e966caeab168bcc489e4","label":"security-advisories@github.com"},{"url":"https://github.com/open-telemetry/opentelemetry-ebpf-profiler/releases/tag/v0.0.202622","label":"security-advisories@github.com"},{"url":"https://github.com/open-telemetry/opentelemetry-ebpf-profiler/security/advisories/GHSA-f2r5-5m7w-p5cx","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-f2r5-5m7w-p5cx"}],"tags":["nvd","cve.org","ghsa","go"],"epss":0.00139,"epssPercentile":0.03647,"ecosystem":"go","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T19:55:51.663762Z"},"ingestedAt":"2026-06-26T16:43:14.601Z","slug":"CVE-2026-48496","body":"## Overview\n\nOpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to open a nonregular mapping file, such as a FIFO, and block indefinitely, preventing further ELF analysis and causing a denial of service. Version 0.0.202622 contains a patch. No known workarounds are available.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-48496)\n\nAffected packages:\n\n- `go.opentelemetry.io/ebpf-profiler >= 0.0.202527, < 0.0.202622`\n\nPatched in:\n\n- `go.opentelemetry.io/ebpf-profiler 0.0.202622`\n\nSource: https://github.com/advisories/GHSA-f2r5-5m7w-p5cx","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":34.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}