CVE-2026-54704Medium· 6.5▾ SunlitOpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.4%
OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends.
io.opentelemetry.javaagent:opentelemetry-javaagent < 2.28.0-alphaUpgrade to a patched release:
io.opentelemetry.javaagent:opentelemetry-javaagent 2.28.0-alphaConnected by shared product, vendor, weakness, or advisory.
CVE-2026-54712Medium· 5.3OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
CVE-2019-1953Medium· 6.5A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text
CVE-2024-23686Medium· 5.3DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.
CVE-2023-43261High· 7.5An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
CVE-2026-61798High· 8.1netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
CVE-2026-59892High· 7.5OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header