Answer in brief
CVE-2026-54704 records a Medium severity (CVSS 6.5) security vulnerability in OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Answer in brief
CVE-2026-54704 records a Medium severity (CVSS 6.5) security vulnerability in OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Update io.opentelemetry.javaagent:opentelemetry-javaagent to 2.28.0-alpha if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-54704 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| io.opentelemetry.javaagent:opentelemetry-javaagentmaven | <2.28.0-alpha | 2.28.0-alpha |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-54704 records a Medium severity (CVSS 6.5) security vulnerability in OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for io.opentelemetry.javaagent:opentelemetry-javaagent.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate io.opentelemetry.javaagent:opentelemetry-javaagent to 2.28.0-alpha if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-54704 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| io.opentelemetry.javaagent:opentelemetry-javaagentmaven | <2.28.0-alpha | 2.28.0-alpha |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-54704 records a Medium severity (CVSS 6.5) security vulnerability in OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for io.opentelemetry.javaagent:opentelemetry-javaagent.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardOpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends. This issue has been fixed in version 2.28.0.
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends. This issue has been fixed in version 2.28.0.