{"schema_version":"1.9.0","id":"GHSA-j8p6-96vp-f3r9","published":"2026-05-18T20:20:03Z","modified":"2026-06-25T23:11:08.758950037Z","aliases":["CVE-2026-45685","GO-2026-5456"],"summary":"OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages","details":"### Summary\n\nMalformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry agent and cause a denial of service. The parser operates on raw attacker-controlled network payloads before the input is fully validated, so a single crafted message can terminate telemetry collection for the affected process or node.\n\n### Details\n\nMongoDB parsing support was introduced by commit `2070f568a` (`Add Initial support for mongodb`), so the explicit released version minimum affected is `v0.1.0`.\n\nThere are two related panic conditions in released `go.opentelemetry.io/obi` versions:\n\n- In `v0.1.0` through `v0.3.0`, `parseOpMessage` reads OP_MSG flag bits from `buf[msgHeaderSize:msgHeaderSize+int32Size]` without first ensuring the buffer is at least `msgHeaderSize + int32Size` bytes long. A truncated OP_MSG packet can therefore trigger a slice-bounds panic before the parser returns an error.\n- In `v0.1.0` through `v0.3.0`, `parseSections` consumes the section type byte and then reads the document-sequence length from `buf[offSet:offSet+int32Size]` without re-validating that enough bytes remain after the type byte. A malformed document-sequence section can therefore trigger another slice-bounds panic.\n- In `v0.1.0` through `v0.8.0`, `parseFirstField` assumes the collection name for collection-scoped commands is always a string and performs an unchecked type assertion on `field.Value`. A malformed BSON document can therefore trigger a runtime panic with `interface conversion` instead of returning a parse error.\n\nThe bounds-check panic was fixed by commit `3aa58cdaaa97fbb72f8ef4c3609ae425aacaf8bb` (`Fix MongoDB client panic`), which first appears in release `v0.4.0`. The unchecked BSON type assertion is still present in `v0.8.0`.\n\nBecause this code runs while decoding attacker-controlled MongoDB traffic, the failure mode is process termination rather than graceful rejection of invalid input. In deployments where the telemetry agent monitors traffic from untrusted or partially trusted clients, a single malformed packet can terminate collection until the agent is restarted.\n\nAffected code paths are in `pkg/ebpf/common/mongo_detect_transform.go` and correspond to `parseOpMessage`, `parseSections`, and `parseFirstField`.\n\n### PoC\n\nThe following reproductions are fully self-contained. They create a temporary test file inside an affected checkout and then run `go test` against the real parser code in the repository.\n\n1. Reproduce the `v0.1.0` through `v0.3.0` bounds-check panics:\n\n   ```bash\n   git clone https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation.git obi-poc\n   cd obi-poc\n   git checkout v0.3.0\n\n   cat > pkg/ebpf/common/mongo_security_poc_test.go <<'EOF'\n   package ebpfcommon\n\n   import \"testing\"\n\n   func TestSecurityPoCParseOpMessageShortPanics(t *testing.T) {\n\t   parseOpMessage(make([]byte, 16), 0, false, nil)\n   }\n\n   func TestSecurityPoCParseSectionsShortDocSequencePanics(t *testing.T) {\n\t   parseSections([]byte{byte(sectionTypeDocumentSequence), 0x01, 0x02, 0x03})\n   }\n   EOF\n\n   go test ./pkg/ebpf/common -run 'TestSecurityPoCParseOpMessageShortPanics|TestSecurityPoCParseSectionsShortDocSequencePanics' -count=1\n   ```\n\n   Expected result:\n\n   - `TestSecurityPoCParseOpMessageShortPanics` panics with a message similar to `slice bounds out of range [:20] with capacity 16`\n   - `TestSecurityPoCParseSectionsShortDocSequencePanics` panics with a message similar to `slice bounds out of range [:5] with capacity 4`\n\n1. Reproduce the `v0.1.0` through `v0.8.0` unchecked BSON type-assertion panic:\n\n   ```bash\n   git clone https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation.git obi-poc\n   cd obi-poc\n   git checkout v0.8.0\n\n   cat > pkg/ebpf/common/mongo_security_poc_test.go <<'EOF'\n   package ebpfcommon\n\n   import (\n\t   \"testing\"\n\n\t   \"go.mongodb.org/mongo-driver/v2/bson\"\n   )\n\n   func TestSecurityPoCParseFirstFieldTypeAssertionPanics(t *testing.T) {\n\t   parseFirstField(bson.E{Key: commFind, Value: int32(123)})\n   }\n   EOF\n\n   go test ./pkg/ebpf/common -run TestSecurityPoCParseFirstFieldTypeAssertionPanics -count=1\n   ```\n\n   Expected result: panic with a message similar to `interface conversion: interface {} is int32, not string`.\n\n### Impact\n\nThis is a remote denial-of-service vulnerability in the MongoDB protocol parser. Any deployment that enables MongoDB parsing and processes attacker-controlled or malformed MongoDB traffic is impacted. Successful exploitation lets an unauthenticated attacker crash the telemetry agent by sending a crafted OP_MSG packet or malformed BSON document, causing loss of observability until the process is restarted.","affected":[{"package":{"name":"go.opentelemetry.io/obi","ecosystem":"Go","purl":"pkg:golang/go.opentelemetry.io/obi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.9.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-j8p6-96vp-f3r9/GHSA-j8p6-96vp-f3r9.json"}}],"references":[{"type":"WEB","url":"https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/security/advisories/GHSA-j8p6-96vp-f3r9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45685"},{"type":"PACKAGE","url":"https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation"},{"type":"WEB","url":"https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/releases/tag/v0.9.0"}],"database_specific":{"cwe_ids":["CWE-20","CWE-248","CWE-704"],"github_reviewed":true,"github_reviewed_at":"2026-05-18T20:20:03Z","nvd_published_at":"2026-06-02T16:16:43Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}