Junglewise Threat Intelligence

CVE-2026-54704: OpenTelemetry Java Instrumentation information disclosure in JDBC auto-instrumentation

CVE-2026-54704 · Severity: medium · CVSS 6.5 · Published 2026-07-01

Technologies: Opentelemetry-Java-Instrumentation, io.opentelemetry.javaagent:opentelemetry-javaagent (Maven), Opentelemetry-Javaagent. Vendors: Opentelemetry, Maven.

Executive brief

OpenTelemetry Java Instrumentation, a tool used to monitor application performance, contains a flaw that may accidentally record database passwords in plain text. This occurs when database connection strings use double quotes for passwords, causing the sensitive information to be stored in monitoring logs and exported to external observability platforms. If an unauthorized person gains access to these logs or the monitoring backend, they could obtain credentials to access the organization's databases.

Technical details

A vulnerability in the JDBC auto-instrumentation component of OpenTelemetry Java Instrumentation (CWE-532) fails to properly sanitize sensitive information during SQL CONNECT statement processing. Specifically, when a password in a connection string is enclosed in double quotes, the sanitization logic is bypassed. This results in clear-text database credentials being recorded as span attributes within traces. These traces are then exported to configured observability backends, potentially exposing credentials to any user with access to the telemetry data. The issue is fixed in version 2.28.0-alpha.

Affected products

  • OpenTelemetry opentelemetry-javaagent < 2.28.0-alpha

Timeline

  • 2026-06-09: patched: Initial patch released in version 2.28.0-alpha
  • 2026-07-01: advisory: NVD publication date
  • 2026-07-29: disclosed: GitHub Advisory published

References

Related threats