CVE-2026-104872: Multiple @opentelemetry/instrumentation-* packages expose database username via unconditional db.user span attribute
OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, and @opentelemetry/instrumentation-mysql2, 0.46.0 of @opentelemetry/instrumentation-oracledb, 0.73.0 of @opentelemetry/instrumentation-pg, and 0.40.0 of @opentelemetry/instrumentation-tedious, the packages add the database connection username to every instrumented database operation as the db.user span attribute. The attribute is emitted by default and is not controlled by enhancedDatabaseReporting or another opt-in setting. Configured observability backends therefore receive database account names that may expose service topology, role or environment information, and account naming patterns. This issue is fixed in versions 0.66.0, 0.65.0, 0.67.0, 0.46.0, 0.73.0, and 0.40.0 of the respective packages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@opentelemetry/instrumentation-cassandra-driverto a version that resolves this vulnerability.Fixed in 0.66.0 - Upgrade
Upgrade
@opentelemetry/instrumentation-knexto a version that resolves this vulnerability.Fixed in 0.65.0 - Upgrade
Upgrade
@opentelemetry/instrumentation-mongooseto a version that resolves this vulnerability.Fixed in 0.67.0 - Upgrade
Upgrade
@opentelemetry/instrumentation-mysqlto a version that resolves this vulnerability.Fixed in 0.67.0 - Upgrade
Upgrade
@opentelemetry/instrumentation-mysql2to a version that resolves this vulnerability.Fixed in 0.67.0 - Upgrade
Upgrade
@opentelemetry/instrumentation-oracledbto a version that resolves this vulnerability.Fixed in 0.46.0 - Upgrade
Upgrade
@opentelemetry/instrumentation-pgto a version that resolves this vulnerability.Fixed in 0.73.0 - Upgrade
Upgrade
@opentelemetry/instrumentation-tediousto a version that resolves this vulnerability.Fixed in 0.40.0
Event History
Frequently Asked Questions
Are applications affected when enhanced database reporting is disabled?
Yes. The db.user span attribute is emitted by default and is not controlled by enhancedDatabaseReporting or another opt-in setting.
Who can obtain the exposed information?
Configured observability backends receive the database account names. Exposure therefore affects users or systems able to access the exported telemetry in those backends.
How can I determine whether telemetry has already exposed database usernames?
Inspect exported spans for the db.user attribute and check whether affected database instrumentation packages are below their fixed versions. The attribute is added to every instrumented database operation by vulnerable package versions.
Which versions remediate the issue?
Upgrade cassandra-driver to 0.66.0, knex to 0.65.0, mongoose, mysql, or mysql2 to 0.67.0, oracledb to 0.46.0, pg to 0.73.0, and tedious to 0.40.0.