HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-39883 — OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42....

·Source: NIST NVD

Updated:

Executive Summary

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.

Analysis

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0. CVSS Score: 7. Published: 2026-04-08T21:17:00.697.

Indicators of Compromise (2)

CVE (2)
CVE-2026-24051
CVE-2026-39883
Source Attribution

Originally published by NIST NVD on Apr 8, 2026. Verified by: NIST.

Related Threats