Description
dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply during baggage injection. A remote unauthenticated attacker can send a baggage HTTP header containing many comma-separated key-value pairs or a single very large value. The extraction path allocates map entries while parsing the attacker-controlled header on every request, causing unbounded CPU and memory consumption in an HTTP service where the baggage propagation style is enabled, which is the default for most affected tracers. This can cause denial of service. This issue is fixed in version 1.62.0.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

dd-trace-java, the Datadog APM client for Java, fails to enforce the limits DD_TRACE_BAGGAGE_MAX_ITEMS (default 64) and DD_TRACE_BAGGAGE_MAX_BYTES (default 8192) during W3C baggage extraction before version 1.62.0. A remote unauthenticated attacker can send an HTTP header with many comma‑separated key‑value pairs or a single very large value. While parsing this attacker‑controlled header, the tracer allocates a map entry for each pair on every request, leading to unbounded CPU and memory consumption in services where baggage propagation is enabled—the default for most affected tracers. The resulting resource exhaustion can cause a denial of service. The issue is fixed in v1.62.0.

Affected Systems

The vulnerability affects the Datadog APM Java client known as dd-trace-java or com.datadoghq:dd-java-agent in all releases before 1.62.0.

Risk and Exploitability

The CVSS score of 7.5 classifies this vulnerability as high severity. The EPSS score of <1% indicates a low probability of exploitation in the wild, though the exploit remains possible. The vulnerability requires no authentication; a malicious HTTP request bearing a crafted baggage header can trigger the resource exhaustion on any service using the tracer, which is enabled by default for most installations. The vulnerability is not listed in the CISA KEV catalog, but exposed services remain at risk.

Generated by OpenCVE AI on September 20, 2026 at 23:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade dd-trace-java to version 1.62.0 or later to enforce baggage size limits
  • Verify baggage propagation is not exposed to untrusted inbound traffic and review application configuration
  • If an upgrade is not yet feasible, disable baggage propagation or limit the use of W3C baggage headers in the tracer configuration

Generated by OpenCVE AI on September 20, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-74xj-wh4w-vqxc dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Datadog
Datadog dd-java-agent
Datadog dd-trace-java
Vendors & Products Datadog
Datadog dd-java-agent
Datadog dd-trace-java

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply during baggage injection. A remote unauthenticated attacker can send a baggage HTTP header containing many comma-separated key-value pairs or a single very large value. The extraction path allocates map entries while parsing the attacker-controlled header on every request, causing unbounded CPU and memory consumption in an HTTP service where the baggage propagation style is enabled, which is the default for most affected tracers. This can cause denial of service. This issue is fixed in version 1.62.0.
Title dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Datadog Dd-java-agent Dd-trace-java
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:16:55.404Z

Reserved: 2026-06-04T16:26:05.984Z

Link: CVE-2026-50270

cve-icon Vulnrichment

Updated: 2026-09-14T19:16:37.582Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:17:49.830

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-50270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling