Database Connection User Exposure in OpenTelemetry JavaScript Instrumentation
CVE-2026-104872
5.8MEDIUM
What is CVE-2026-104872?
The OpenTelemetry JavaScript Contrib libraries prior to specified versions expose database connection usernames during telemetry operations. This vulnerability can lead to the unintended disclosure of sensitive information, such as service topology and account naming patterns, to observability backends. It is essential to upgrade to the latest versions to mitigate these risks and ensure that sensitive data is not inadvertently shared.
Affected Version(s)
instrumentation-cassandra-driver < 0.66.0
instrumentation-knex < 0.65.0
instrumentation-mongoose < 0.67.0
