Description
dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply during baggage injection. A remote unauthenticated attacker can send a baggage HTTP header containing many comma-separated key-value pairs or a single very large value. The extraction path allocates entries while parsing the attacker-controlled header on every request, causing unbounded CPU and memory consumption in an HTTP service where the baggage propagation style is enabled, which is the default for most affected tracers. This can cause denial of service. This issue is fixed in version 2.32.0.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the dd‑trace‑rb Ruby client library before version 2.32.0. During extraction of W3C baggage headers, the library does not enforce the configured limits on number of items or total size (DD_TRACE_BAGGAGE_MAX_ITEMS and DD_TRACE_BAGGAGE_MAX_BYTES). An attacker can craft an HTTP header containing a large number of comma‑separated key‑value pairs or a single very large value. As the extractor parses each header on every request, it allocates memory for every parsed entry, resulting in unbounded CPU and memory consumption and triggering a denial of service against any Ruby service that has baggage propagation enabled.

Affected Systems

The flaw affects all Ruby applications that include Datadog’s dd‑trace‑rb library and are running a version earlier than 2.32.0. This includes every release up to and including 2.31.x, regardless of the specific Ruby framework, because baggage propagation is enabled by default in most deployments. The advisory explicitly states that the issue is fixed in version 2.32.0 and later.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity, while the EPSS score is < 1% and the vulnerability has not been listed in CISA’s KEV catalog, indicating no known active exploitation at the time of analysis. The exploit requires no authentication or privileged access; the attacker simply sends a crafted baggage header over HTTP. The attack path is straightforward: trigger the extraction routine by sending many or large values, exhausting CPU or memory resources of the service, which results in a denial of service. The lack of enforced limits makes the risk considerable for services that expose public endpoints and rely on default baggage propagation behavior.

Generated by OpenCVE AI on September 20, 2026 at 23:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the dd‑trace‑rb library to version 2.32.0 or later, which enforces the DD_TRACE_BAGGAGE_MAX_ITEMS and DD_TRACE_BAGGAGE_MAX_BYTES checks during extraction.
  • If an immediate update is not feasible, configure the tracer or the application to disable baggage propagation for incoming traffic from untrusted clients, or globally turn off baggage processing.
  • Apply a temporary measure at the application entry point or reverse proxy to strip or truncate baggage headers before they reach the tracer, or enforce custom limits on header size or number of items in code before forwarding requests to the tracer.

Generated by OpenCVE AI on September 20, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p5f6-rccc-jv98 dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply during baggage injection. A remote unauthenticated attacker can send a baggage HTTP header containing many comma-separated key-value pairs or a single very large value. The extraction path allocates entries while parsing the attacker-controlled header on every request, causing unbounded CPU and memory consumption in an HTTP service where the baggage propagation style is enabled, which is the default for most affected tracers. This can cause denial of service. This issue is fixed in version 2.32.0.
Title dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T17:38:12.401Z

Reserved: 2026-06-04T16:26:05.984Z

Link: CVE-2026-50276

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:17:49.990

Modified: 2026-09-25T14:10:13.927

Link: CVE-2026-50276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling