GHSA-rwqx-fvqh-6wm4MediumCVSS 6.5

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

Published
July 29, 2026
Last Modified
July 29, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends.

🎯 Affected products1

  • maven/io.opentelemetry.javaagent:opentelemetry-javaagent:< 2.28.0-alpha

🔗 References (6)