npm package report

Is @opentelemetry/instrumentation-mongoose safe?

1 known vulnerability, worst severity MODERATE.

// reach

0 direct dependencies

none carry a known advisory

    3 packages depend on it

    an advisory here reaches each of them

    Create a free accountfor every dependency path, dependent and what to upgrade
    // ai model usage

    Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


    cvss
    0.0
    medium

    severity out of 10

    epss
    0.00%
    low

    chance of exploitation in 30 days, 14th percentile of all CVEs

    xyz score
    not scored

    CyberXYZ composite out of 10

    fig. 01 — GHSA-qqmp-wf37-98f9, the advisory selected below

    // 1 advisories

    GHSA-qqmp-wf37-98f9

    MODERATECVE-2026-104872
    // impact

    Multiple @opentelemetry/instrumentation- packages recorded the database connection username as the db.user span attribute on every instrumented database operation. This attribute was emitted unconditionally — it was not gated by enhancedDatabaseReporting or any other opt-in flag, and it was the default behaviour for all users of the affected packages until the patched releases shipped on 2026-07-23.

    The attribute is forwarded to every configured observability backend (Jaeger, Zipkin, Datadog, OTLP collectors, etc.). Depending on the database account naming convention in use, the exported value may reveal:

    • Internal service account names that disclose architecture topology.
    • Role-encoded usernames (e.g. adminreadwrite, appreadonlyprod) useful for privilege inference.
    • Database account naming patterns useful for credential enumeration.

    Affected packages (all are vulnerable from the first published version through the version listed below):

    | Package | Vulnerable range | Patched version | |---------|-----------------|-----------------| | @opentelemetry/instrumentation-cassandra-driver | < 0.66.0 | 0.66.0 | | @opentelemetry/instrumentation-knex | < 0.65.0 | 0.65.0 | | @opentelemetry/instrumentation-mongoose | < 0.67.0 | 0.67.0 | | @opentelemetry/instrumentation-mysql | < 0.67.0 | 0.67.0 | | @opentelemetry/instrumentation-mysql2 | < 0.67.0 | 0.67.0 | | @opentelemetry/instrumentation-oracledb | < 0.46.0 | 0.46.0 | | @opentelemetry/instrumentation-pg | < 0.73.0 | 0.73.0 | | @opentelemetry/instrumentation-tedious | < 0.40.0 | 0.40.0 |

    // patches

    Fixed in the coordinated release on 2026-07-23 via feat!: only emit stable http, network and database attributes (#3585).

    Upgrade to the patched version listed in the table above for each instrumentation package in use.

    // workarounds

    No configuration-level workaround exists in the affected versions: the db.user attribute cannot be suppressed without patching. As a partial mitigation, a custom SpanProcessor can be used to strip db.user from spans before they leave the process:

    // Example: drop db.user in a custom SpanProcessor
    class StripDbUserProcessor implements SpanProcessor {
      onStart(span: Span) {
        span.setAttribute('db.user', null);
      }
      onEnd() {}
      shutdown() { return Promise.resolve(); }
      forceFlush() { return Promise.resolve(); }
    }

    Users who control the downstream collector can also filter the attribute at the collector pipeline level.

    // cvss v3.1 vector

    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

    Attack vector
    Network
    Attack complexity
    Low
    Privileges required
    None
    User interaction
    None
    Scope
    Changed
    Confidentiality
    Low
    Integrity
    None
    Availability
    None

    Checked 2026-10-06 at 02:09 UTC. The most recent advisory here was published 2026-10-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.

    Think a verdict here is wrong? Tell us — we respond within 2 business days.