GHSA-rwqx-fvqh-6wm4: OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Summary
OpenTelemetry Java Instrumentation has a vulnerability in its JDBC auto-instrumentation (automatic code monitoring for database connections) that logs database passwords in clear text, meaning anyone who reads the logs can see the actual passwords. This is a confidentiality issue because it exposes sensitive authentication information that should remain secret.
Vulnerability Details
EPSS: 0.2%
Yes
July 29, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-rwqx-fvqh-6wm4
First tracked: July 29, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 72%