VDB

CVE-2026-48496

CVE-2026-48496 PUBLISHED CVSS 6.2 MEDIUM

Reported by GitHub_M · Published September 11, 2026

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to open a nonregular mapping file, such as a FIFO, and block indefinitely, preventing further ELF analysis and causing a denial of service. Version 0.0.202622 contains a patch. No known workarounds are available.

Risk Scores

CVSS 3.1
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
open-telemetryopentelemetry-ebpf-profiler>= 0.0.202527, < 0.0.202622
chainguardelastic-agent-9.30, 0, 0
open-telemetryopentelemetry-ebpf-profiler>= 0.0.202527, < 0.0.202622, >= 0.0.202527, < 0.0.202622
chainguardelastic-agent-fips-8.190, 0, 0
chainguardelastic-agent-8.190, 0, 0
chainguardelastic-agent-9.40, 0, 0
chainguardelastic-agent-fips-9.30, 0, 0
chainguardelastic-agent-fips-9.40, 0, 0
go.opentelemetry.ioebpf-profiler0.0.202527

Timeline

  • Jun 23, 2026 CVE Published
  • Jun 24, 2026 Security Advisory
  • Sep 12, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›