CVE-2026-50275 PUBLISHED

Datadog PHP Tracer: Improper parsing of W3C baggage headers may lead to DoS

Assigner: GitHub_M
Reserved: 04.06.2026 Published: 17.09.2026 Updated: 17.09.2026

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers.c parses incoming W3C baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES. A remote unauthenticated client can send an arbitrarily large number of comma-separated key-value pairs or a single oversized value, causing the tracer to allocate hash-map entries and consume unbounded CPU and memory on each request. Baggage extraction is enabled by default in most affected deployments unless baggage is removed from DD_TRACE_PROPAGATION_STYLE or DD_TRACE_PROPAGATION_STYLE_EXTRACT. This issue is fixed in version 1.19.2.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor DataDog
Product dd-trace-php
Versions
  • Version < 1.19.2 is affected

References

Problem Types

  • CWE-770: Allocation of Resources Without Limits or Throttling CWE