CVE-2026-81192
HighAdvisory
Published 16 Sept 2026In the index since 17 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.0
- base score, highest
- EPSS
- 0.001
- 4th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3
- of 17,805 indexed, latest versions
- Container images
- 3
- deployed by those charts
- Fix available
- 1 of 1
- affected package
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
Carried by container images the latest versions of 3 of 17,805 indexed charts deploy, on 3 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| OpenTelemetry.Resources.Hostnuget | 0.1.0-beta.3, 1.14.0-beta.1, 1.15.1-beta.1 | 1.16.0-beta.2 | 3 |
- OSV records
- GHSA-v8pv-4842-x354
Charts affected
3 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| opentelemetry-demoopentelemetry-helmOfficialVerified publisher | 0.42.0 | 1 of 34See more | 20,097 |
| opentelemetry-demogpg-dev | 0.33.8 | 1 of 27See more | 49,912 |
| fdi-dotstatsuitestatcan | 0.3.5 | 1 of 3See more | 582 |
Container images carrying it
3 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| siscc/ | 6cf1145566f0 | OpenTelemetry.Resources.Host | 1.16.0-beta.2 | 1 |
| ghcr.io/ | 6d051840bb29 | OpenTelemetry.Resources.Host | 1.16.0-beta.2 | 1 |
| ghcr.io/ | bfd9d13ac58a | OpenTelemetry.Resources.Host | 1.16.0-beta.2 | 1 |