CVE-2026-45679: OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
(updated )
OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-controlled or sensitive values, this behavior can exfiltrate tokens, PII, or other confidential input into telemetry backends and inject untrusted text into downstream analysis systems.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-45679 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →