Threat Advisory

OpenTelemetry Vulnerability Exposes Database Username via Unconditional DB User Span Attribute

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-104872 with a CVSS score of 5.8 is an information disclosure vulnerability affecting @opentelemetry/instrumentation-cassandra-driver, @opentelemetry/instrumentation-knex, @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, @opentelemetry/instrumentation-mysql2, @opentelemetry/instrumentation-oracledb, @opentelemetry/instrumentation-pg and @opentelemetry/instrumentation-tedious, where unconditional db.user span attributes expose database usernames that are forwarded to configured observability backends and may reveal internal service account names, role-encoded usernames or database account naming patterns useful for privilege inference; the vulnerability has an attack vector of network, attack complexity of low, privileges required of none and user interaction of none.

RECOMMENDATIONS:

  • We recommend you to update @opentelemetry/instrumentation-cassandra-driver, @opentelemetry/instrumentation-knex, @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, @opentelemetry/instrumentation-mysql2, @opentelemetry/instrumentation-oracledb, @opentelemetry/instrumentation-pg and @opentelemetry/instrumentation-tedious to below version:
  • https://github.com/advisories/GHSA-qqmp-wf37-98f9/

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-104872 with a CVSS score of 5.8 is an information disclosure vulnerability affecting @opentelemetry/instrumentation-cassandra-driver, @opentelemetry/instrumentation-knex, @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, @opentelemetry/instrumentation-mysql2, @opentelemetry/instrumentation-oracledb, @opentelemetry/instrumentation-pg and @opentelemetry/instrumentation-tedious, where unconditional db.user span attributes expose database usernames that are forwarded to configured observability backends and may reveal internal service account names, role-encoded usernames or database account naming patterns useful for privilege inference; the vulnerability has an attack vector of network, attack complexity of low, privileges required of none and user interaction of none.

RECOMMENDATIONS:

  • We recommend you to update @opentelemetry/instrumentation-cassandra-driver, @opentelemetry/instrumentation-knex, @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, @opentelemetry/instrumentation-mysql2, @opentelemetry/instrumentation-oracledb, @opentelemetry/instrumentation-pg and @opentelemetry/instrumentation-tedious to below version:
  • https://github.com/advisories/GHSA-qqmp-wf37-98f9/

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu