Unknown · @Opentelemetry/Instrumentation · CVE-2026-54704
**Name of the Vulnerable Software and Affected Versions**
OpenTelemetry Java Instrumentation versions prior to 2.28.0
**Description**
The JDBC auto-instrumentation fails to sanitize passwords in SQL CONNECT statements when the password is enclosed in double quotes. This leads to clear-text database passwords being included in trace span attributes and subsequently exported to observability backends.
**Recommendations**
Update to version 2.28.0.