{"id":"CVE-2026-54704","aliases":["GHSA-rwqx-fvqh-6wm4"],"title":"OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords","summary":"OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords","severity":"medium","cvss":6.5,"cwe":["CWE-532"],"vendor":"opentelemetry","product":"io.opentelemetry.javaagent:opentelemetry-javaagent","ecosystem":"maven","affected":["io.opentelemetry.javaagent:opentelemetry-javaagent < 2.28.0-alpha"],"patched":["io.opentelemetry.javaagent:opentelemetry-javaagent 2.28.0-alpha"],"published":"2026-07-29","updated":"2026-07-29","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-rwqx-fvqh-6wm4","references":[{"url":"https://github.com/open-telemetry/opentelemetry-java-instrumentation/security/advisories/GHSA-rwqx-fvqh-6wm4"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54704"},{"url":"https://github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18754"},{"url":"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/7ac7fa6fda6c2e3b65bc5d3c6eba050311a49511"},{"url":"https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases/tag/v2.28.0"},{"url":"https://github.com/advisories/GHSA-rwqx-fvqh-6wm4"}],"tags":["ghsa","maven"],"epss":0.00379,"epssPercentile":0.31853,"ingestedAt":"2026-07-29T17:48:50.011Z","slug":"CVE-2026-54704","body":"## Overview\n\nOpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends.\n\n## Affected packages\n\n- `io.opentelemetry.javaagent:opentelemetry-javaagent < 2.28.0-alpha`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `io.opentelemetry.javaagent:opentelemetry-javaagent 2.28.0-alpha`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}