HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-39883 — OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42....
·Source: NIST NVD
Updated:
Executive Summary
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.
Analysis
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0. CVSS Score: 7. Published: 2026-04-08T21:17:00.697.