Back

HIGH

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

Published Jul 17, 2026

Description

Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path. A remote, unauthenticated attacker can send a request whose baggage header contains an arbitrarily large number of comma-separated key-value pairs or a single very large value, causing unbounded CPU and memory consumption and enabling a remote denial of service against HTTP services with baggage propagation enabled. This issue is fixed in version 4.8.2.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jul 17, 2026
Updated Jul 20, 2026
Reserved Jun 4, 2026

CISA Vulnrichment

Updated Jul 20, 2026

NVD

Status Awaiting Analysis
Modified Jul 23, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Jul 17, 2026
Updated Jul 20, 2026