Impact
Prior to version 2.1.0, DataDog’s dd‑trace‑cpp library parsed W3C baggage headers without enforcing the configured maximum item or byte limits during extraction. An attacker could send a header crafted with a large number of comma‑separated key/value pairs or a single very large value, causing the library to allocate a large hash‑map and consume excessive CPU and memory per request. This behavior can lead to a denial of service for the affected application. The flaw is therefore a classic Denial of Service vulnerability.
Affected Systems
The affected product is DataDog’s dd‑trace‑cpp, the open‑source distributed tracing client for C++. Users of any version older than 2.1.0 that have baggage extraction enabled—typically the default for most services—are vulnerable. The vulnerability applies to any internet‑facing service that uses this library to trace requests over HTTP or other protocols that support W3C baggage headers.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1% suggests low expected exploitation likelihood as of the latest analysis, and the issue is not listed in the CISA KEV catalog. Nevertheless, the flaw can be exploited remotely by any unauthenticated user who can inject HTTP requests containing crafted baggage headers, for example via public endpoints. Because the flaw is exercised on every request that parses baggage, a single attacker can generate significant denial of service traffic without authentication.
OpenCVE Enrichment