Executive brief
dd-trace-cpp is Datadog's distributed tracing library for C++ applications. The library fails to enforce size limits when parsing incoming W3C baggage headers, allowing attackers to send maliciously crafted headers with many key-value pairs or very large values. This causes unbounded memory and CPU consumption on receiving services, leading to service unavailability—a significant risk for internet-facing applications relying on the tracer.
Technical details
The vulnerability is a denial-of-service flaw in baggage header parsing (CWE-770: allocation of resources without limits or throttling). Prior to version 2.1.0, dd-trace-cpp extracts W3C baggage headers without enforcing the DD_TRACE_BAGGAGE_MAX_ITEMS and DD_TRACE_BAGGAGE_MAX_BYTES limits that are applied during injection. An unauthenticated remote attacker can craft headers with numerous comma-separated key-value pairs or extremely large values, triggering per-request hash-map allocations and exhausting memory and CPU. Baggage extraction is enabled by default in most tracers unless explicitly disabled via DD_TRACE_PROPAGATION_STYLE configuration. The fix is available in version 2.1.0, which applies the same limits to extraction as injection.
Affected products
- Datadog dd-trace-cpp before 2.1.0
Timeline
- 2026-09-17: disclosed
- 2026-05-04: patched: Fix merged in version 2.1.0