CVE-2026-54704
ADVISORY - githubSummary
OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends.
EPSS Score: 0.00224 (0.131)
Common Weakness Enumeration (CWE)
ADVISORY - github
Insertion of Sensitive Information into Log File
GitHub
CREATED
UPDATED
ADVISORY IDGHSA-rwqx-fvqh-6wm4
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)