A AegiFlow
MEDIUMCVSS 6.5EPSS 0.2%

CVE-2026-54704

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

Published
2026-07-29
Modified
2026-07-29
EPSS percentile
13%
Aliases
GHSA-rwqx-fvqh-6wm4
Sources
github-advisory

Summary

OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenio.opentelemetry.javaagent:opentelemetry-javaagent2.28.0-alpha

Remediation: Upgrade to 2.28.0-alpha or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.