The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
GHSA-qqmp-wf37-98f9: Multiple @opentelemetry/instrumentation-* packages expose database username via unconditional db.user span attribute
- Identifiers
- CVE-2026-104872GHSA-qqmp-wf37-98f9
- Published
- Record updated
Summary
Multiple @opentelemetry/instrumentation-* packages (cassandra-driver, knex, mongoose, mysql, mysql2, oracledb, pg, tedious) record the database connection username as the db.user span attribute on every instrumented operation. The attribute is emitted unconditionally, not behind enhancedDatabaseReporting, and is forwarded to every configured observability backend, where it can reveal service account names or role-encoded usernames useful for privilege inference.
Mitigation
Upgrade each affected instrumentation package to its patched version: cassandra-driver 0.66.0, knex 0.65.0, mongoose 0.67.0, mysql 0.67.0, mysql2 0.67.0, oracledb 0.46.0, pg 0.73.0, tedious 0.40.0. The fix shipped 2026-07-23 in PR #3585. No configuration-level workaround exists; partial mitigations are a custom SpanProcessor that sets db.user to null in onStart, or filtering the attribute at the collector pipeline.