CVE-2026-54704

ADVISORY - github

Summary

OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends.

EPSS Score: 0.00224 (0.131)

Common Weakness Enumeration (CWE)

ADVISORY - github

Insertion of Sensitive Information into Log File


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in