CVE-2026-54704: Linuxfoundation Opentelemetry Instrumentation For Java

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends. This issue has been fixed in version 2.28.0.

Affected products

  • Linuxfoundation Opentelemetry Instrumentation For Java: before 2.28.0 (fixed in 2.28.0)

Published 2026-07-01. Last modified 2026-07-06.