CVE-2026-24051
HighAdvisory
Published 2 Feb 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.0
- base score, highest
- EPSS
- 0.002
- 6th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 554
- of 17,787 indexed, latest versions
- Container images
- 563
- deployed by those charts
- Fix available
- 1 of 1
- affected package
OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking
Carried by container images the latest versions of 554 of 17,787 indexed charts deploy, on 563 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| go.opentelemetry.io/ | v1.21.0, v1.22.0, v1.23.0, v1.23.1+16 more | 1.40.0 | 563 |
- OSV records
- GHSA-9h8m-3fm2-qjrq
- Also known as
- GO-2026-4394
Charts affected
554 by stars
Container images carrying it
563 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| registry.gitlab.com/ | 86d87291ffd4 | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.gitlab.com/ | 9b9d1ed86b6a | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.gitlab.com/ | 301847adfe16 | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.k8s.io/ | 6ef10d108e0e | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.k8s.io/ | 7b172f42533c | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.k8s.io/ | f9f4dfd733ab | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.k8s.io/ | 94caebb89dcf | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.k8s.io/ | 8b9a78d101a1 | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.k8s.io/ | e36c08168342 | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.k8s.io/ | 1c0419326500 | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.k8s.io/ | db3800085a09 | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.k8s.io/ | be59d0556508 | go.opentelemetry.io/ | 1.40.0 | 1 |
| registry.k8s.io/ | 4a95d94e57ad | go.opentelemetry.io/ | 1.40.0 | 1 |