Untrusted Search Path Affecting go.opentelemetry.io/otel/sdk/resource package, versions >=1.21.0 <1.40.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.16% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GOOPENTELEMETRYIOOTELSDKRESOURCE-15182758
  • published4 Feb 2026
  • disclosed2 Feb 2026
  • creditMorielHarush

Introduced: 2 Feb 2026

CVE-2026-24051  (opens in a new tab)
CWE-426  (opens in a new tab)

How to fix?

Upgrade go.opentelemetry.io/otel/sdk/resource to version 1.40.0 or higher.

Overview

Affected versions of this package are vulnerable to Untrusted Search Path in resource detection code which executes ioreg, when the PATH environment variable is modified to include a malicious executable. An attacker can execute arbitrary code within the context of the application by placing a malicious binary earlier in the search path.

Note: This vulnerability is only exploitable on MacOS/Darwin systems.

References

CVSS Base Scores

version 4.0
version 3.1