GHSA-qqmp-wf37-98f9: Medium severity npm/@opentelemetry/instrumentation-pg vulnerability

Published Oct 5, 2026
·
Updated

Impact

Multiple @opentelemetry/instrumentation- packages recorded the database connection username as the db.user span attribute on every instrumented database operation. This attribute was emitted unconditionally — it was not gated by enhancedDatabaseReporting or any other opt-in flag, and it was the default behaviour for all users of the affected packages until the patched releases shipped on 2026-07-23.

The attribute is forwarded to every configured observability backend (Jaeger, Zipkin, Datadog, OTLP collectors, etc.). Depending on the database account naming convention in use, the exported value may reveal:

- Internal service account names that disclose architecture topology. - Role-encoded usernames (e.g. adminreadwrite, appreadonlyprod) useful for privilege inference. - Database account naming patterns useful for credential enumeration.

Affected packages (all are vulnerable from the first published version through the version listed below):

| Package | Vulnerable range | Patched version | |---------|-----------------|-----------------| | @opentelemetry/instrumentation-cassandra-driver | < 0.66.0 | 0.66.0 | | @opentelemetry/instrumentation-knex | < 0.65.0 | 0.65.0 | | @opentelemetry/instrumentation-mongoose | < 0.67.0 | 0.67.0 | | @opentelemetry/instrumentation-mysql | < 0.67.0 | 0.67.0 | | @opentelemetry/instrumentation-mysql2 | < 0.67.0 | 0.67.0 | | @opentelemetry/instrumentation-oracledb | < 0.46.0 | 0.46.0 | | @opentelemetry/instrumentation-pg | < 0.73.0 | 0.73.0 | | @opentelemetry/instrumentation-tedious | < 0.40.0 | 0.40.0 |

Patches

Fixed in the coordinated release on 2026-07-23 via feat!: only emit stable http, network and database attributes (#3585).

Upgrade to the patched version listed in the table above for each instrumentation package in use.

Workarounds

No configuration-level workaround exists in the affected versions: the db.user attribute cannot be suppressed without patching. As a partial mitigation, a custom SpanProcessor can be used to strip db.user from spans before they leave the process:

ts // Example: drop db.user in a custom SpanProcessor class StripDbUserProcessor implements SpanProcessor { onStart(span: Span) { span.setAttribute('db.user', null); } onEnd() {} shutdown() { return Promise.resolve(); } forceFlush() { return Promise.resolve(); } }

Users who control the downstream collector can also filter the attribute at the collector pipeline level.

Affected Software

8 affected componentsFixes available
npm/@opentelemetry/instrumentation-pg<0.73.0
0.73.0
npm/@opentelemetry/instrumentation-mysql2<0.67.0
0.67.0
npm/@opentelemetry/instrumentation-knex<0.65.0
0.65.0
npm/@opentelemetry/instrumentation-mysql<0.67.0
0.67.0
npm/@opentelemetry/instrumentation-mongoose<0.67.0
0.67.0
npm/@opentelemetry/instrumentation-oracledb<0.46.0
0.46.0
npm/@opentelemetry/instrumentation-tedious<0.40.0
0.40.0
npm/@opentelemetry/instrumentation-cassandra-driver<0.66.0
0.66.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@opentelemetry/instrumentation-pg to a version that resolves this vulnerability.

    Fixed in 0.73.0
  2. Upgrade

    Upgrade npm/@opentelemetry/instrumentation-mysql2 to a version that resolves this vulnerability.

    Fixed in 0.67.0
  3. Upgrade

    Upgrade npm/@opentelemetry/instrumentation-knex to a version that resolves this vulnerability.

    Fixed in 0.65.0
  4. Upgrade

    Upgrade npm/@opentelemetry/instrumentation-mysql to a version that resolves this vulnerability.

    Fixed in 0.67.0
  5. Upgrade

    Upgrade npm/@opentelemetry/instrumentation-mongoose to a version that resolves this vulnerability.

    Fixed in 0.67.0
  6. Upgrade

    Upgrade npm/@opentelemetry/instrumentation-oracledb to a version that resolves this vulnerability.

    Fixed in 0.46.0
  7. Upgrade

    Upgrade npm/@opentelemetry/instrumentation-tedious to a version that resolves this vulnerability.

    Fixed in 0.40.0
  8. Upgrade

    Upgrade npm/@opentelemetry/instrumentation-cassandra-driver to a version that resolves this vulnerability.

    Fixed in 0.66.0
  9. Upgrade

    Upgrade @opentelemetry/instrumentation-cassandra-driver to a version that resolves this vulnerability.

    Fixed in 0.66.0
  10. Upgrade

    Upgrade @opentelemetry/instrumentation-knex to a version that resolves this vulnerability.

    Fixed in 0.65.0
  11. Upgrade

    Upgrade @opentelemetry/instrumentation-mongoose to a version that resolves this vulnerability.

    Fixed in 0.67.0
  12. Upgrade

    Upgrade @opentelemetry/instrumentation-mysql2 to a version that resolves this vulnerability.

    Fixed in 0.67.0
  13. Upgrade

    Upgrade @opentelemetry/instrumentation-mysql to a version that resolves this vulnerability.

    Fixed in 0.67.0
  14. Upgrade

    Upgrade @opentelemetry/instrumentation-oracledb to a version that resolves this vulnerability.

    Fixed in 0.46.0
  15. Upgrade

    Upgrade @opentelemetry/instrumentation-pg to a version that resolves this vulnerability.

    Fixed in 0.73.0
  16. Upgrade

    Upgrade @opentelemetry/instrumentation-tedious to a version that resolves this vulnerability.

    Fixed in 0.40.0
  17. Compensating control

    Before spans leave the process, use a custom SpanProcessor to strip the db.user attribute by setting span.setAttribute('db.user', null), or filter the db.user attribute in the downstream collector pipeline.

Event History

Oct 5, 2026
Advisory Published
via GitHub·10:52 PM
Data Sourced
via GitHub·10:52 PM
DescriptionSeverityWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203