Impact
This vulnerability allows a remote, unauthenticated attacker to send an arbitrarily large or malformed W3C baggage header. The Datadog PHP Tracer, before version 1.19.2, does not enforce limits on the number of baggage items or the total size of baggage values. When such a header is processed, the tracer allocates hash‑map entries for each key and consumes CPU and memory without bound. The primary impact is an availability loss, as the affected process can become unresponsive or crash due to resource exhaustion.
Affected Systems
The issue affects deployments of DataDog dd-trace-php on any PHP application that employs the default baggage extraction. All versions earlier than 1.19.2 are vulnerable. Upgrading to 1.19.2 or later removes the flaw by enforcing DD_TRACE_BAGGAGE_MAX_ITEMS and DD_TRACE_BAGGAGE_MAX_BYTES limits.
Risk and Exploitability
The CVSS score for this bug is 7.5, indicating a high severity. The EPSS score is below 1 %, suggesting that, at present, exploitation is considered low probability, although the vulnerability remains publicly documented. Because the attacker only needs to craft an HTTP header, the required effort is minimal. The tracer’s default configuration extracts baggage in most installations, so the path to exploitation is straightforward. The bug is not listed in the CISA KEV catalog, but the lack of a public exploit does not reduce the risk of a DoS event if an attacker chooses to test it.
OpenCVE Enrichment