Impact
The vulnerability lies in the dd‑trace‑rb Ruby client library before version 2.32.0. During extraction of W3C baggage headers, the library does not enforce the configured limits on number of items or total size (DD_TRACE_BAGGAGE_MAX_ITEMS and DD_TRACE_BAGGAGE_MAX_BYTES). An attacker can craft an HTTP header containing a large number of comma‑separated key‑value pairs or a single very large value. As the extractor parses each header on every request, it allocates memory for every parsed entry, resulting in unbounded CPU and memory consumption and triggering a denial of service against any Ruby service that has baggage propagation enabled.
Affected Systems
The flaw affects all Ruby applications that include Datadog’s dd‑trace‑rb library and are running a version earlier than 2.32.0. This includes every release up to and including 2.31.x, regardless of the specific Ruby framework, because baggage propagation is enabled by default in most deployments. The advisory explicitly states that the issue is fixed in version 2.32.0 and later.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, while the EPSS score is < 1% and the vulnerability has not been listed in CISA’s KEV catalog, indicating no known active exploitation at the time of analysis. The exploit requires no authentication or privileged access; the attacker simply sends a crafted baggage header over HTTP. The attack path is straightforward: trigger the extraction routine by sending many or large values, exhausting CPU or memory resources of the service, which results in a denial of service. The lack of enforced limits makes the risk considerable for services that expose public endpoints and rely on default baggage propagation behavior.
OpenCVE Enrichment
Github GHSA