GHSA-qqmp-wf37-98f9

Suggest an improvement
Source
https://github.com/advisories/GHSA-qqmp-wf37-98f9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qqmp-wf37-98f9/GHSA-qqmp-wf37-98f9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qqmp-wf37-98f9
Aliases
Published
2026-10-05T22:52:44Z
Modified
2026-10-05T23:00:05Z
Severity
  • 5.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
Multiple @opentelemetry/instrumentation-* packages expose database username via unconditional db.user span attribute
Details

Impact

Multiple @opentelemetry/instrumentation-* packages recorded the database connection username as the db.user span attribute on every instrumented database operation. This attribute was emitted unconditionally — it was not gated by enhancedDatabaseReporting or any other opt-in flag, and it was the default behaviour for all users of the affected packages until the patched releases shipped on 2026-07-23.

The attribute is forwarded to every configured observability backend (Jaeger, Zipkin, Datadog, OTLP collectors, etc.). Depending on the database account naming convention in use, the exported value may reveal:

  • Internal service account names that disclose architecture topology.
  • Role-encoded usernames (e.g. admin_readwrite, app_readonly_prod) useful for privilege inference.
  • Database account naming patterns useful for credential enumeration.

Affected packages (all are vulnerable from the first published version through the version listed below):

Package Vulnerable range Patched version
@opentelemetry/instrumentation-cassandra-driver < 0.66.0 0.66.0
@opentelemetry/instrumentation-knex < 0.65.0 0.65.0
@opentelemetry/instrumentation-mongoose < 0.67.0 0.67.0
@opentelemetry/instrumentation-mysql < 0.67.0 0.67.0
@opentelemetry/instrumentation-mysql2 < 0.67.0 0.67.0
@opentelemetry/instrumentation-oracledb < 0.46.0 0.46.0
@opentelemetry/instrumentation-pg < 0.73.0 0.73.0
@opentelemetry/instrumentation-tedious < 0.40.0 0.40.0

Patches

Fixed in the coordinated release on 2026-07-23 via feat!: only emit stable http, network and database attributes (#3585).

Upgrade to the patched version listed in the table above for each instrumentation package in use.

Workarounds

No configuration-level workaround exists in the affected versions: the db.user attribute cannot be suppressed without patching. As a partial mitigation, a custom SpanProcessor can be used to strip db.user from spans before they leave the process:

// Example: drop db.user in a custom SpanProcessor
class StripDbUserProcessor implements SpanProcessor {
  onStart(span: Span) {
    span.setAttribute('db.user', null);
  }
  onEnd() {}
  shutdown() { return Promise.resolve(); }
  forceFlush() { return Promise.resolve(); }
}

Users who control the downstream collector can also filter the attribute at the collector pipeline level.

Database specific
{
    "cwe_ids":  [
        "CWE-532"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T22:52:44Z",
    "nvd_published_at":  "2026-10-02T20:17:01Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm
@opentelemetry/instrumentation-cassandra-driver

Package

Name
@opentelemetry/instrumentation-cassandra-driver
View open source insights on deps.dev
Purl
pkg:npm/%40opentelemetry/instrumentation-cassandra-driver

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.66.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qqmp-wf37-98f9/GHSA-qqmp-wf37-98f9.json"
@opentelemetry/instrumentation-tedious

Package

Name
@opentelemetry/instrumentation-tedious
View open source insights on deps.dev
Purl
pkg:npm/%40opentelemetry/instrumentation-tedious

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.40.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qqmp-wf37-98f9/GHSA-qqmp-wf37-98f9.json"
@opentelemetry/instrumentation-oracledb

Package

Name
@opentelemetry/instrumentation-oracledb
View open source insights on deps.dev
Purl
pkg:npm/%40opentelemetry/instrumentation-oracledb

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.46.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qqmp-wf37-98f9/GHSA-qqmp-wf37-98f9.json"
@opentelemetry/instrumentation-mongoose

Package

Name
@opentelemetry/instrumentation-mongoose
View open source insights on deps.dev
Purl
pkg:npm/%40opentelemetry/instrumentation-mongoose

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.67.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qqmp-wf37-98f9/GHSA-qqmp-wf37-98f9.json"
@opentelemetry/instrumentation-mysql

Package

Name
@opentelemetry/instrumentation-mysql
View open source insights on deps.dev
Purl
pkg:npm/%40opentelemetry/instrumentation-mysql

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.67.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qqmp-wf37-98f9/GHSA-qqmp-wf37-98f9.json"
@opentelemetry/instrumentation-knex

Package

Name
@opentelemetry/instrumentation-knex
View open source insights on deps.dev
Purl
pkg:npm/%40opentelemetry/instrumentation-knex

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.65.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qqmp-wf37-98f9/GHSA-qqmp-wf37-98f9.json"
@opentelemetry/instrumentation-mysql2

Package

Name
@opentelemetry/instrumentation-mysql2
View open source insights on deps.dev
Purl
pkg:npm/%40opentelemetry/instrumentation-mysql2

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.67.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qqmp-wf37-98f9/GHSA-qqmp-wf37-98f9.json"
@opentelemetry/instrumentation-pg

Package

Name
@opentelemetry/instrumentation-pg
View open source insights on deps.dev
Purl
pkg:npm/%40opentelemetry/instrumentation-pg

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.73.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qqmp-wf37-98f9/GHSA-qqmp-wf37-98f9.json"