CVE-2026-54704: Linuxfoundation Opentelemetry Instrumentation For Java
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends. This issue has been fixed in version 2.28.0.
Affected products
- Linuxfoundation Opentelemetry Instrumentation For Java: before 2.28.0 (fixed in 2.28.0)
Published 2026-07-01. Last modified 2026-07-06.