Impact
dd-trace-java, the Datadog APM client for Java, fails to enforce the limits DD_TRACE_BAGGAGE_MAX_ITEMS (default 64) and DD_TRACE_BAGGAGE_MAX_BYTES (default 8192) during W3C baggage extraction before version 1.62.0. A remote unauthenticated attacker can send an HTTP header with many comma‑separated key‑value pairs or a single very large value. While parsing this attacker‑controlled header, the tracer allocates a map entry for each pair on every request, leading to unbounded CPU and memory consumption in services where baggage propagation is enabled—the default for most affected tracers. The resulting resource exhaustion can cause a denial of service. The issue is fixed in v1.62.0.
Affected Systems
The vulnerability affects the Datadog APM Java client known as dd-trace-java or com.datadoghq:dd-java-agent in all releases before 1.62.0.
Risk and Exploitability
The CVSS score of 7.5 classifies this vulnerability as high severity. The EPSS score of <1% indicates a low probability of exploitation in the wild, though the exploit remains possible. The vulnerability requires no authentication; a malicious HTTP request bearing a crafted baggage header can trigger the resource exhaustion on any service using the tracer, which is enabled by default for most installations. The vulnerability is not listed in the CISA KEV catalog, but exposed services remain at risk.
OpenCVE Enrichment
Github GHSA