CVE-2026-104872 with a CVSS score of 5.8 is an information disclosure vulnerability affecting @opentelemetry/instrumentation-cassandra-driver, @opentelemetry/instrumentation-knex, @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, @opentelemetry/instrumentation-mysql2, @opentelemetry/instrumentation-oracledb, @opentelemetry/instrumentation-pg and @opentelemetry/instrumentation-tedious, where unconditional db.user span attributes expose database usernames that are forwarded to configured observability backends and may reveal internal service account names, role-encoded usernames or database account naming patterns useful for privilege inference; the vulnerability has an attack vector of network, attack complexity of low, privileges required of none and user interaction of none.
The following reports contain further technical details:[/subscribe_to_unlock_form]
CVE-2026-104872 with a CVSS score of 5.8 is an information disclosure vulnerability affecting @opentelemetry/instrumentation-cassandra-driver, @opentelemetry/instrumentation-knex, @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, @opentelemetry/instrumentation-mysql2, @opentelemetry/instrumentation-oracledb, @opentelemetry/instrumentation-pg and @opentelemetry/instrumentation-tedious, where unconditional db.user span attributes expose database usernames that are forwarded to configured observability backends and may reveal internal service account names, role-encoded usernames or database account naming patterns useful for privilege inference; the vulnerability has an attack vector of network, attack complexity of low, privileges required of none and user interaction of none.
The following reports contain further technical details:[emaillocker id="1283"]
[/emaillocker]