Executive brief
Datadog's Java tracing library, used to monitor application performance, contains a flaw in how it processes certain web request headers. An unauthenticated attacker can send specially crafted requests that cause the application to consume excessive CPU and memory. This can lead to a denial-of-service (DoS) condition, making the affected web service unavailable to legitimate users.
Technical details
The dd-trace-java library fails to enforce item-count or byte-size limits when extracting W3C baggage headers, despite having limits (DD_TRACE_BAGGAGE_MAX_ITEMS and DD_TRACE_BAGGAGE_MAX_BYTES) for injection. A remote, unauthenticated attacker can exploit this by sending an HTTP request with a baggage header containing an extremely large number of key-value pairs or a single massive value. The tracer's extraction logic allocates a hash-map entry for every pair, leading to unbounded CPU and memory consumption. This vulnerability is present in the default configuration where baggage propagation is enabled. The issue is resolved in version 1.62.0.
Affected products
- Datadog dd-trace-java < 1.62.0
Timeline
- 2026-06-05: disclosed: Initial publication by Datadog
- 2026-07-15: advisory: GitHub Advisory reviewed and updated