MEDIUM
OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals
Published Jun 2, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.17%
Description
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In long-running instrumented JVMs, repeated connection churn can therefore grow the queue without bound and exhaust heap memory. This issue has been patched in version 0.9.0.
Affected products
-
- Version < 0.9.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Open-Telemetry | Opentelemetry-Ebpf-Instrumentation | n/a |
|
- < 0.9.0
No data.
No Red Hat product state for this CVE.
go.opentelemetry.io/obi
Go
Introduced 0 Fixed 0.9.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | go.opentelemetry.io/obi | 0 | 0.9.0 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33950 Advisory
- https://github.com/advisories/GHSA-962q-hwm5-52x5 Advisory
- https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/releases/tag/v0.9.0 x_refsource_MISCProductRelease Notes
- https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/security/advisories/GHSA-962q-hwm5-52x5 exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-45682
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33950 | Advisory | |
| https://github.com/advisories/GHSA-962q-hwm5-52x5 | Advisory | |
| https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/releases/tag/v0.9.0 | x_refsource_MISCProductRelease Notes | |
| https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/security/advisories/GHSA-962q-hwm5-52x5 | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-45682 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 2, 2026
Updated Jun 2, 2026
Reserved May 12, 2026
Link CVE-2026-45682
CISA Vulnrichment
Updated Jun 2, 2026
ENISA EUVD
EUVD-2026-33950 GHSA-962Q-HWM5-52X5 Assigner GitHub_M
Published Jun 2, 2026
Updated Jun 2, 2026
Exploited since n/a
Link EUVD-2026-33950