Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50274

Опубликовано: 17 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path. A remote, unauthenticated attacker can send a request whose baggage header contains an arbitrarily large number of comma-separated key-value pairs or a single very large value, causing unbounded CPU and memory consumption and enabling a remote denial of service against HTTP services with baggage propagation enabled. This issue is fixed in version 2.8.1.

A flaw was found in Datadog dd-trace-go, a Go client library. A remote, unauthenticated attacker can exploit this vulnerability by sending a request with a specially crafted baggage header containing an arbitrarily large number of key-value pairs or a very large single value. This can lead to unbounded CPU and memory consumption, resulting in a denial of service (DoS) against HTTP services that have baggage propagation enabled.

Отчет

Red Hat Advanced Cluster Management for Kubernetes and OpenShift Container Platform 4.21+ ship versions of the Datadog dd-trace-go v2 library prior to v2.8.1 that are vulnerable to this denial-of-service flaw in W3C baggage header parsing. OpenShift Container Platform 4.12 through 4.20 ships dd-trace-go v1, which does not implement W3C baggage propagation and is not affected.

Меры по смягчению последствий

If Datadog APM tracing with W3C baggage propagation is enabled, disable the baggage propagator by setting the DD_TRACE_PROPAGATION_STYLE environment variable to exclude 'baggage'.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/lighthouse-agent-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/lighthouse-coredns-rhel9Affected
Red Hat OpenShift Container Platform 4openshift4/ose-corednsNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-coredns-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2501951github.com/DataDog/dd-trace-go: Datadog dd-trace-go: Denial of Service via malicious baggage headers

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
20 дней назад

Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path. A remote, unauthenticated attacker can send a request whose baggage header contains an arbitrarily large number of comma-separated key-value pairs or a single very large value, causing unbounded CPU and memory consumption and enabling a remote denial of service against HTTP services with baggage propagation enabled. This issue is fixed in version 2.8.1.

CVSS3: 7.5
github
22 дня назад

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

7.5 High

CVSS3