Description
dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on the extraction path, even though those limits are enforced during injection. A remote unauthenticated attacker can send a header containing many comma-separated key-value pairs or one very large value, causing per-request hash-map allocation and unbounded CPU and memory consumption. Baggage extraction is enabled by default in most affected tracers unless baggage is removed from DD_TRACE_PROPAGATION_STYLE or DD_TRACE_PROPAGATION_STYLE_EXTRACT, so affected internet-facing services can be denied service. This issue is fixed in version 2.1.0.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Prior to version 2.1.0, DataDog’s dd‑trace‑cpp library parsed W3C baggage headers without enforcing the configured maximum item or byte limits during extraction. An attacker could send a header crafted with a large number of comma‑separated key/value pairs or a single very large value, causing the library to allocate a large hash‑map and consume excessive CPU and memory per request. This behavior can lead to a denial of service for the affected application. The flaw is therefore a classic Denial of Service vulnerability.

Affected Systems

The affected product is DataDog’s dd‑trace‑cpp, the open‑source distributed tracing client for C++. Users of any version older than 2.1.0 that have baggage extraction enabled—typically the default for most services—are vulnerable. The vulnerability applies to any internet‑facing service that uses this library to trace requests over HTTP or other protocols that support W3C baggage headers.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1% suggests low expected exploitation likelihood as of the latest analysis, and the issue is not listed in the CISA KEV catalog. Nevertheless, the flaw can be exploited remotely by any unauthenticated user who can inject HTTP requests containing crafted baggage headers, for example via public endpoints. Because the flaw is exercised on every request that parses baggage, a single attacker can generate significant denial of service traffic without authentication.

Generated by OpenCVE AI on September 19, 2026 at 01:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade dd‑trace‑cpp to version 2.1.0 or later, where limits on baggage size and item count are enforced during extraction.
  • If an upgrade cannot be performed immediately, temporarily disable baggage extraction by unsetting DD_TRACE_PROPAGATION_STYLE or DD_TRACE_PROPAGATION_STYLE_EXTRACT environment variables so that the library skips parsing baggage headers.
  • Implement application‑level request filtering or rate limiting to reject requests containing unusually large or numerous baggage headers, and monitor traffic for abnormal patterns.

Generated by OpenCVE AI on September 19, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Datadog
Datadog dd-trace-cpp
Vendors & Products Datadog
Datadog dd-trace-cpp

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on the extraction path, even though those limits are enforced during injection. A remote unauthenticated attacker can send a header containing many comma-separated key-value pairs or one very large value, causing per-request hash-map allocation and unbounded CPU and memory consumption. Baggage extraction is enabled by default in most affected tracers unless baggage is removed from DD_TRACE_PROPAGATION_STYLE or DD_TRACE_PROPAGATION_STYLE_EXTRACT, so affected internet-facing services can be denied service. This issue is fixed in version 2.1.0.
Title dd-trace-cpp: Improper parsing of W3C baggage headers may lead to DoS
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Datadog Dd-trace-cpp
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T21:12:32.522Z

Reserved: 2026-06-04T16:26:05.985Z

Link: CVE-2026-50277

cve-icon Vulnrichment

Updated: 2026-09-21T21:12:27.928Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T21:17:14.243

Modified: 2026-09-24T21:16:28.120

Link: CVE-2026-50277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling