Junglewise Threat Intelligence

CVE-2026-50277: Datadog dd-trace-cpp denial of service in baggage header extraction

CVE-2026-50277 · Severity: high · CVSS 7.5 · Published 2026-09-17

Vendors: Datadog.

Executive brief

dd-trace-cpp is Datadog's distributed tracing library for C++ applications. The library fails to enforce size limits when parsing incoming W3C baggage headers, allowing attackers to send maliciously crafted headers with many key-value pairs or very large values. This causes unbounded memory and CPU consumption on receiving services, leading to service unavailability—a significant risk for internet-facing applications relying on the tracer.

Technical details

The vulnerability is a denial-of-service flaw in baggage header parsing (CWE-770: allocation of resources without limits or throttling). Prior to version 2.1.0, dd-trace-cpp extracts W3C baggage headers without enforcing the DD_TRACE_BAGGAGE_MAX_ITEMS and DD_TRACE_BAGGAGE_MAX_BYTES limits that are applied during injection. An unauthenticated remote attacker can craft headers with numerous comma-separated key-value pairs or extremely large values, triggering per-request hash-map allocations and exhausting memory and CPU. Baggage extraction is enabled by default in most tracers unless explicitly disabled via DD_TRACE_PROPAGATION_STYLE configuration. The fix is available in version 2.1.0, which applies the same limits to extraction as injection.

Affected products

  • Datadog dd-trace-cpp before 2.1.0

Timeline

  • 2026-09-17: disclosed
  • 2026-05-04: patched: Fix merged in version 2.1.0

References