7.5
CVE-2026-50270
- EPSS -
- Veröffentlicht 14.09.2026 17:03:39
- Zuletzt bearbeitet 30.09.2026 17:43:24
- Erkennungen
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply during baggage injection. A remote unauthenticated attacker can send a baggage HTTP header containing many comma-separated key-value pairs or a single very large value. The extraction path allocates map entries while parsing the attacker-controlled header on every request, causing unbounded CPU and memory consumption in an HTTP service where the baggage propagation style is enabled, which is the default for most affected tracers. This can cause denial of service. This issue is fixed in version 1.62.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerDataDog
≫
Produkt
dd-trace-java
Version
< 1.62.0
Status
affected
Herstellercom.datadoghq
≫
Produkt
dd-java-agent
Version
< 1.62.0
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://github.com/DataDog/dd-trace-java/security/advisories/GHSA-74xj-wh4w-vqxc
https://github.com/DataDog/dd-trace-java/pull/11265
https://github.com/DataDog/dd-trace-java/commit/16c6a5fd1fed71cef6c35f69122f19f5ee242757
https://github.com/DataDog/dd-trace-java/releases/tag/v1.62.0