PT-2026-95086 · Datadog · Datadog Php Tracer
CVE-2026-50275
·
Published
2026-09-17
·
Updated
2026-09-23
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Datadog PHP Tracer versions prior to 1.19.2
Description
The
ddtrace deserialize baggage function in ext/distributed tracing headers.c fails to enforce the DD TRACE BAGGAGE MAX ITEMS or DD TRACE BAGGAGE MAX BYTES limits when parsing incoming W3C baggage HTTP headers. A remote unauthenticated client can exploit this by sending a single oversized value or an excessive number of comma-separated key-value pairs. This leads to unbounded CPU and memory consumption due to the allocation of hash-map entries on each request. Baggage extraction is typically enabled by default unless it is removed from DD TRACE PROPAGATION STYLE or DD TRACE PROPAGATION STYLE EXTRACT.Recommendations
Update to version 1.19.2.
As a temporary mitigation, remove baggage from
DD TRACE PROPAGATION STYLE or DD TRACE PROPAGATION STYLE EXTRACT to disable baggage extraction.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datadog Php Tracer