{"schema_version":1,"title":"Datadog vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in Datadog: 1 in the last 7 days and 10 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-77620, was published on 22 September 2026.","url":"https://junglewise.ai/threats/vendors/datadog","json_url":"https://junglewise.ai/threats/vendors/datadog.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/datadog","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":9,"all_time":15,"critical":1,"exploited":0,"last_7_days":1,"last_30_days":6,"last_90_days":10,"last_365_days":15},"latest":[{"cve":"CVE-2026-77620","epss":0.0052,"slug":"cve-2026-77620-vector-is-a-high-performance-observability-data-pipeline-from-0","title":"Vector logstash source denial of service via nested compression","severity":"info","exploited":false,"published_at":"2026-09-22T16:17:55.5+00:00","url":"https://junglewise.ai/threats/cve-2026-77620-vector-is-a-high-performance-observability-data-pipeline-from-0"},{"cve":"CVE-2026-50277","cvss":7.5,"epss":0.0079,"slug":"cve-2026-50277-datadog-dd-trace-cpp-denial-of-service-in-baggage-header","title":"Datadog dd-trace-cpp denial of service in baggage header extraction","severity":"high","exploited":false,"published_at":"2026-09-17T21:17:14.243+00:00","url":"https://junglewise.ai/threats/cve-2026-50277-datadog-dd-trace-cpp-denial-of-service-in-baggage-header"},{"cve":"CVE-2026-50275","cvss":7.5,"epss":0.0068,"slug":"cve-2026-50275-datadog-php-tracer-denial-of-service-via-unbounded-baggage","title":"Datadog PHP Tracer denial of service via unbounded baggage parsing","severity":"high","exploited":false,"published_at":"2026-09-17T21:17:14.073+00:00","url":"https://junglewise.ai/threats/cve-2026-50275-datadog-php-tracer-denial-of-service-via-unbounded-baggage"},{"cve":"CVE-2026-50276","cvss":7.5,"epss":0.0079,"slug":"cve-2026-50276-datadog-dd-trace-rb-denial-of-service-in-w3c-baggage-parsing","title":"dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which","severity":"high","exploited":false,"published_at":"2026-09-14T18:17:49.99+00:00","url":"https://junglewise.ai/threats/cve-2026-50276-datadog-dd-trace-rb-denial-of-service-in-w3c-baggage-parsing"},{"cve":"CVE-2026-50270","cvss":7.5,"epss":0.0079,"slug":"cve-2026-50270-datadog-dd-trace-java-denial-of-service-via-w3c-baggage-headers","title":"dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which d","severity":"high","exploited":false,"published_at":"2026-09-14T18:17:49.83+00:00","url":"https://junglewise.ai/threats/cve-2026-50270-datadog-dd-trace-java-denial-of-service-via-w3c-baggage-headers"},{"cve":"CVE-2026-54788","cvss":7.5,"epss":0.0079,"slug":"cve-2026-54788-datadog-dd-trace-rs-unbounded-w3c-tracestate-parsing-dos","title":"dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/trac","severity":"high","exploited":false,"published_at":"2026-08-28T20:18:17.95+00:00","url":"https://junglewise.ai/threats/cve-2026-54788-datadog-dd-trace-rs-unbounded-w3c-tracestate-parsing-dos"},{"cve":"CVE-2026-50274","cvss":7.5,"slug":"cve-2026-50274-datadog-dd-trace-go-denial-of-service-in-w3c-baggage-header","title":"Datadog dd-trace-go denial of service in W3C baggage header parsing","severity":"high","exploited":false,"published_at":"2026-07-17T21:17:07.337+00:00","url":"https://junglewise.ai/threats/cve-2026-50274-datadog-dd-trace-go-denial-of-service-in-w3c-baggage-header"},{"cve":"CVE-2026-50272","cvss":7.5,"epss":0.0079,"slug":"cve-2026-50272-datadog-dd-trace-js-denial-of-service-via-unbounded-baggage","title":"DataDog dd-trace-js denial of service via unbounded baggage extraction","severity":"high","exploited":false,"published_at":"2026-07-17T21:17:07.2+00:00","url":"https://junglewise.ai/threats/cve-2026-50272-datadog-dd-trace-js-denial-of-service-via-unbounded-baggage"},{"cve":"CVE-2026-50271","cvss":7.5,"epss":0.0079,"slug":"cve-2026-50271-datadog-dd-trace-py-denial-of-service-in-w3c-baggage-parsing","title":"Datadog dd-trace-py Denial of Service in W3C baggage parsing","severity":"high","exploited":false,"published_at":"2026-07-17T21:17:07.07+00:00","url":"https://junglewise.ai/threats/cve-2026-50271-datadog-dd-trace-py-denial-of-service-in-w3c-baggage-parsing"},{"cve":"CVE-2026-50273","cvss":7.5,"slug":"cve-2026-50273-datadog-net-tracer-denial-of-service-in-w3c-baggage-parsing","title":"Datadog .NET Tracer Denial of Service in W3C baggage parsing","severity":"high","exploited":false,"published_at":"2026-07-17T18:17:16.84+00:00","url":"https://junglewise.ai/threats/cve-2026-50273-datadog-net-tracer-denial-of-service-in-w3c-baggage-parsing"},{"cve":"CVE-2026-39197","cvss":7.5,"slug":"cve-2026-39197-datadog-vector-denial-of-service-via-memory-exhaustion-in-http","title":"Datadog Vector Denial of Service via memory exhaustion in HTTP and gRPC ingest","severity":"info","exploited":false,"published_at":"2026-06-15T20:16:27.677+00:00","url":"https://junglewise.ai/threats/cve-2026-39197-datadog-vector-denial-of-service-via-memory-exhaustion-in-http"},{"cve":"CVE-2026-39196","cvss":0,"slug":"cve-2026-39196-datadog-vector-sql-injection-in-clickhouse-sink-keypartitioner","title":"Datadog Vector SQL injection in ClickHouse sink KeyPartitioner","severity":"info","exploited":false,"published_at":"2026-06-15T20:16:27.567+00:00","url":"https://junglewise.ai/threats/cve-2026-39196-datadog-vector-sql-injection-in-clickhouse-sink-keypartitioner"},{"cve":"CVE-2026-9270","slug":"cve-2026-9270-datadog-dogstatsd-metric-injection-in-perl-library","title":"DataDog DogStatsd metric injection in Perl library","severity":"info","exploited":false,"published_at":"2026-06-05T16:16:41.78+00:00","url":"https://junglewise.ai/threats/cve-2026-9270-datadog-dogstatsd-metric-injection-in-perl-library"},{"cve":"CVE-2026-11362","slug":"cve-2026-11362-datadog-dogstatsd-metric-injection-in-perl-library-event-tags","title":"DataDog DogStatsd metric injection in Perl library event tags","severity":"info","exploited":false,"published_at":"2026-06-05T16:16:41.277+00:00","url":"https://junglewise.ai/threats/cve-2026-11362-datadog-dogstatsd-metric-injection-in-perl-library-event-tags"},{"cve":"CVE-2026-33728","cvss":9.8,"epss":0.0099,"slug":"cve-2026-33728-datadog-dd-trace-java-unsafe-deserialization-in-rmi","title":"Datadog dd-trace-java unsafe deserialization in RMI instrumentation","severity":"critical","exploited":false,"published_at":"2026-03-27T01:16:20.203+00:00","url":"https://junglewise.ai/threats/cve-2026-33728-datadog-dd-trace-java-unsafe-deserialization-in-rmi"}],"vendor":{"hub":true,"name":"Datadog","slug":"datadog","homepage":"https://www.datadoghq.com/","description":"Datadog is an observability service for cloud-scale applications, providing monitoring of servers, databases, tools, and services through a SaaS-based data analytics platform.","url":"https://junglewise.ai/threats/vendors/datadog"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2026-33728","cvss":9.8,"epss":0.0099,"slug":"cve-2026-33728-datadog-dd-trace-java-unsafe-deserialization-in-rmi","title":"Datadog dd-trace-java unsafe deserialization in RMI instrumentation","severity":"critical","exploited":false,"published_at":"2026-03-27T01:16:20.203+00:00","url":"https://junglewise.ai/threats/cve-2026-33728-datadog-dd-trace-java-unsafe-deserialization-in-rmi"},{"cve":"CVE-2026-50277","cvss":7.5,"epss":0.0079,"slug":"cve-2026-50277-datadog-dd-trace-cpp-denial-of-service-in-baggage-header","title":"Datadog dd-trace-cpp denial of service in baggage header extraction","severity":"high","exploited":false,"published_at":"2026-09-17T21:17:14.243+00:00","url":"https://junglewise.ai/threats/cve-2026-50277-datadog-dd-trace-cpp-denial-of-service-in-baggage-header"},{"cve":"CVE-2026-50276","cvss":7.5,"epss":0.0079,"slug":"cve-2026-50276-datadog-dd-trace-rb-denial-of-service-in-w3c-baggage-parsing","title":"dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which","severity":"high","exploited":false,"published_at":"2026-09-14T18:17:49.99+00:00","url":"https://junglewise.ai/threats/cve-2026-50276-datadog-dd-trace-rb-denial-of-service-in-w3c-baggage-parsing"},{"cve":"CVE-2026-50270","cvss":7.5,"epss":0.0079,"slug":"cve-2026-50270-datadog-dd-trace-java-denial-of-service-via-w3c-baggage-headers","title":"dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which d","severity":"high","exploited":false,"published_at":"2026-09-14T18:17:49.83+00:00","url":"https://junglewise.ai/threats/cve-2026-50270-datadog-dd-trace-java-denial-of-service-via-w3c-baggage-headers"},{"cve":"CVE-2026-54788","cvss":7.5,"epss":0.0079,"slug":"cve-2026-54788-datadog-dd-trace-rs-unbounded-w3c-tracestate-parsing-dos","title":"dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/trac","severity":"high","exploited":false,"published_at":"2026-08-28T20:18:17.95+00:00","url":"https://junglewise.ai/threats/cve-2026-54788-datadog-dd-trace-rs-unbounded-w3c-tracestate-parsing-dos"},{"cve":"CVE-2026-50272","cvss":7.5,"epss":0.0079,"slug":"cve-2026-50272-datadog-dd-trace-js-denial-of-service-via-unbounded-baggage","title":"DataDog dd-trace-js denial of service via unbounded baggage extraction","severity":"high","exploited":false,"published_at":"2026-07-17T21:17:07.2+00:00","url":"https://junglewise.ai/threats/cve-2026-50272-datadog-dd-trace-js-denial-of-service-via-unbounded-baggage"},{"cve":"CVE-2026-50271","cvss":7.5,"epss":0.0079,"slug":"cve-2026-50271-datadog-dd-trace-py-denial-of-service-in-w3c-baggage-parsing","title":"Datadog dd-trace-py Denial of Service in W3C baggage parsing","severity":"high","exploited":false,"published_at":"2026-07-17T21:17:07.07+00:00","url":"https://junglewise.ai/threats/cve-2026-50271-datadog-dd-trace-py-denial-of-service-in-w3c-baggage-parsing"},{"cve":"CVE-2026-50275","cvss":7.5,"epss":0.0068,"slug":"cve-2026-50275-datadog-php-tracer-denial-of-service-via-unbounded-baggage","title":"Datadog PHP Tracer denial of service via unbounded baggage parsing","severity":"high","exploited":false,"published_at":"2026-09-17T21:17:14.073+00:00","url":"https://junglewise.ai/threats/cve-2026-50275-datadog-php-tracer-denial-of-service-via-unbounded-baggage"},{"cve":"CVE-2026-50274","cvss":7.5,"slug":"cve-2026-50274-datadog-dd-trace-go-denial-of-service-in-w3c-baggage-header","title":"Datadog dd-trace-go denial of service in W3C baggage header parsing","severity":"high","exploited":false,"published_at":"2026-07-17T21:17:07.337+00:00","url":"https://junglewise.ai/threats/cve-2026-50274-datadog-dd-trace-go-denial-of-service-in-w3c-baggage-header"},{"cve":"CVE-2026-50273","cvss":7.5,"slug":"cve-2026-50273-datadog-net-tracer-denial-of-service-in-w3c-baggage-parsing","title":"Datadog .NET Tracer Denial of Service in W3C baggage parsing","severity":"high","exploited":false,"published_at":"2026-07-17T18:17:16.84+00:00","url":"https://junglewise.ai/threats/cve-2026-50273-datadog-net-tracer-denial-of-service-in-w3c-baggage-parsing"}],"generated_at":"2026-09-26T14:07:00.158513+00:00","technologies":[]}