PT-2026-95087 · Datadog · Dd-Trace-Cpp
CVE-2026-50277
·
Published
2026-09-17
·
Updated
2026-09-17
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
dd-trace-cpp versions prior to 2.1.0
Description
The library parses incoming W3C baggage headers without enforcing the
DD TRACE BAGGAGE MAX ITEMS or DD TRACE BAGGAGE MAX BYTES limits during the extraction path. A remote unauthenticated attacker can send a header containing a large value or numerous comma-separated key-value pairs, leading to per-request hash-map allocation and unbounded CPU and memory consumption. This can result in a denial of service for internet-facing services, as baggage extraction is enabled by default unless removed from DD TRACE PROPAGATION STYLE or DD TRACE PROPAGATION STYLE EXTRACT.Recommendations
Update to version 2.1.0.
As a temporary mitigation, remove baggage from
DD TRACE PROPAGATION STYLE or DD TRACE PROPAGATION STYLE EXTRACT to disable baggage extraction.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dd-Trace-Cpp