CVE-2026-54704

ADVISORY - github

Summary

OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends.

EPSS Score: 0.00224 (0.131)

Common Weakness Enumeration (CWE)

ADVISORY - github

Insertion of Sensitive Information into Log File


GitHub

CREATED

UPDATED

EXPLOITABILITY SCORE

2.8

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.5medium