---
id: CVE-2026-104872
title: >-
  OpenTelemetry JavaScript Contrib provides instrumentation libraries for
  collecting telemetry from JavaScript applications
summary: >-
  OpenTelemetry JavaScript Contrib provides instrumentation libraries for
  collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of
  @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of
  @opentelemetry/instrumentat…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-532
vendor: open-telemetry
product: opentelemetry-js-contrib
affected:
  - opentelemetry-js-contrib < 27e172a9e0d549559056ccd58f27d13467454156
  - instrumentation-cassandra-driver < 0.66.0
  - instrumentation-knex < 0.65.0
  - instrumentation-mongoose < 0.67.0
  - instrumentation-mysql < 0.67.0
  - instrumentation-mysql2 < 0.67.0
  - instrumentation-oracledb < 0.46.0
  - instrumentation-pg < 0.73.0
  - instrumentation-tedious < 0.40.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T20:17:01.067'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104872'
references:
  - url: >-
      https://github.com/open-telemetry/opentelemetry-js-contrib/commit/27e172a9e0d549559056ccd58f27d13467454156
    label: security-advisories@github.com
  - url: >-
      https://github.com/open-telemetry/opentelemetry-js-contrib/commit/5b7dd0e102e940d653e04b08b5a1b721a8271037
    label: security-advisories@github.com
  - url: 'https://github.com/open-telemetry/opentelemetry-js-contrib/pull/3585'
    label: security-advisories@github.com
  - url: >-
      https://github.com/open-telemetry/opentelemetry-js-contrib/security/advisories/GHSA-qqmp-wf37-98f9
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T22:33:09.843Z'
---

## Overview

OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, and @opentelemetry/instrumentation-mysql2, 0.46.0 of @opentelemetry/instrumentation-oracledb, 0.73.0 of @opentelemetry/instrumentation-pg, and 0.40.0 of @opentelemetry/instrumentation-tedious, the packages add the database connection username to every instrumented database operation as the db.user span attribute. The attribute is emitted by default and is not controlled by enhancedDatabaseReporting or another opt-in setting. Configured observability backends therefore receive database account names that may expose service topology, role or environment information, and account naming patterns. This issue is fixed in versions 0.66.0, 0.65.0, 0.67.0, 0.46.0, 0.73.0, and 0.40.0 of the respective packages.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
