PT-2026-95086 · Datadog · Datadog Php Tracer

CVE-2026-50275

·

Published

2026-09-17

·

Updated

2026-09-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Datadog PHP Tracer versions prior to 1.19.2
Description The ddtrace deserialize baggage function in ext/distributed tracing headers.c fails to enforce the DD TRACE BAGGAGE MAX ITEMS or DD TRACE BAGGAGE MAX BYTES limits when parsing incoming W3C baggage HTTP headers. A remote unauthenticated client can exploit this by sending a single oversized value or an excessive number of comma-separated key-value pairs. This leads to unbounded CPU and memory consumption due to the allocation of hash-map entries on each request. Baggage extraction is typically enabled by default unless it is removed from DD TRACE PROPAGATION STYLE or DD TRACE PROPAGATION STYLE EXTRACT.
Recommendations Update to version 1.19.2. As a temporary mitigation, remove baggage from DD TRACE PROPAGATION STYLE or DD TRACE PROPAGATION STYLE EXTRACT to disable baggage extraction.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50275
GHSA-PHWX-WW2P-CV9V

Affected Products

Datadog Php Tracer