CVE-2026-104872
Received Received - Intake

Information Exposure in OpenTelemetry JavaScript Instrumentation Packages

Vulnerability report for CVE-2026-104872, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, and @opentelemetry/instrumentation-mysql2, 0.46.0 of @opentelemetry/instrumentation-oracledb, 0.73.0 of @opentelemetry/instrumentation-pg, and 0.40.0 of @opentelemetry/instrumentation-tedious, the packages add the database connection username to every instrumented database operation as the db.user span attribute. The attribute is emitted by default and is not controlled by enhancedDatabaseReporting or another opt-in setting. Configured observability backends therefore receive database account names that may expose service topology, role or environment information, and account naming patterns. This issue is fixed in versions 0.66.0, 0.65.0, 0.67.0, 0.46.0, 0.73.0, and 0.40.0 of the respective packages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 19 associated CPEs
Vendor Product Version / Range
opentelemetry instrumentation-amqplib From 0.67.0 (inc)
opentelemetry instrumentation-aws-sdk From 0.67.0 (inc)
opentelemetry instrumentation-document-load From 0.67.0 (inc)
opentelemetry instrumentation-hapi From 0.67.0 (inc)
opentelemetry instrumentation-ioredis From 0.67.0 (inc)
opentelemetry instrumentation-memcached From 0.67.0 (inc)
opentelemetry instrumentation-mongodb From 0.67.0 (inc)
opentelemetry instrumentation-nestjs-core From 0.67.0 (inc)
opentelemetry instrumentation-net From 0.67.0 (inc)
opentelemetry instrumentation-redis From 0.67.0 (inc)
opentelemetry instrumentation-sequelize From 0.67.0 (inc)
opentelemetry instrumentation-cassandra-driver to 0.66.0 (exc)
opentelemetry instrumentation-knex to 0.65.0 (exc)
opentelemetry instrumentation-mongoose to 0.67.0 (exc)
opentelemetry instrumentation-mysql *
opentelemetry instrumentation-mysql2 *
opentelemetry instrumentation-oracledb to 0.46.0 (exc)
opentelemetry instrumentation-pg to 0.73.0 (exc)
opentelemetry instrumentation-tedious to 0.40.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves multiple OpenTelemetry JavaScript instrumentation packages that unconditionally exposed database usernames via the db.user span attribute in all instrumented database operations. The exposed usernames could reveal internal service account names, role-encoded usernames, or database account patterns, potentially aiding privilege inference or credential enumeration.

Detection Guidance

Check installed versions of affected packages using npm list @opentelemetry/instrumentation-cassandra-driver @opentelemetry/instrumentation-knex @opentelemetry/instrumentation-mongoose @opentelemetry/instrumentation-mysql @opentelemetry/instrumentation-mysql2 @opentelemetry/instrumentation-oracledb @opentelemetry/instrumentation-pg @opentelemetry/instrumentation-tedious. If versions are below the patched releases, the system is vulnerable.

Impact Analysis

The vulnerability could expose sensitive database account information, including service topology, role or environment details, and account naming patterns. This information might be used to infer privileges or enumerate credentials, posing a risk to confidentiality and potentially aiding further attacks.

Compliance Impact

The vulnerability exposes database usernames via span attributes, which could reveal internal service account names, role-encoded usernames, or database account patterns. This may violate GDPR's data minimization principle and HIPAA's minimum necessary standard by exposing unnecessary sensitive information.

Mitigation Strategies

Upgrade affected packages to versions 0.66.0 or higher for cassandra-driver, 0.65.0 for knex, 0.67.0 for mongoose/mysql/mysql2, 0.46.0 for oracledb, 0.73.0 for pg, and 0.40.0 for tedious. Alternatively, implement custom SpanProcessors to strip the db.user attribute or filter it at the collector pipeline level.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104872. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart