{"id":"GHSA-74xj-wh4w-vqxc","summary":"dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS","details":"### Impact\nDatadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing item-count or byte-size limits on the extract path. The DD_TRACE_BAGGAGE_MAX_ITEMS (default 64) and DD_TRACE_BAGGAGE_MAX_BYTES (default 8192) limits were applied only to baggage injection, not extraction. A remote, unauthenticated attacker can send a request whose baggage header contains an arbitrarily large number of comma-separated key-value pairs (or a single very large value). The tracer allocates a hash-map entry for each pair on every request, causing unbounded CPU and memory consumption and enabling a remote Denial of Service against any HTTP service that has the baggage propagation style enabled. The baggage propagation style is enabled by default in most affected tracers, so any internet-facing service that has been instrumented with an affected tracer version is exposed unless the propagation style has been explicitly narrowed.\n\n\n### Patches\nThis is resolved in version 1.62.0 and later of the `dd-trace-java` library.\n\n### Workarounds\nIf users cannot upgrade immediately:\n1. Disable `baggage` extraction by removing `baggage` from `DD_TRACE_PROPAGATION_STYLE` (or `DD_TRACE_PROPAGATION_STYLE_EXTRACT` if set independently).\n2. Cap the maximum HTTP request header size at an upstream proxy or web server (for example, Apache `LimitRequestFieldSize`, Nginx `large_client_header_buffers`, Envoy `max_request_headers_kb`).\n\n\n### Resources\nRelated upstream advisories:\n[opentelemetry-go GHSA-mh2q-q3fh-2475](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-mh2q-q3fh-2475)\n[opentelemetry-dotnet GHSA-g94r-2vxg-569j](https://github.com/open-telemetry/opentelemetry-dotnet/security/advisories/GHSA-g94r-2vxg-569j)","aliases":["CVE-2026-50270"],"modified":"2026-07-29T05:15:34.387802861Z","published":"2026-07-15T22:53:16Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-15T22:53:16Z","nvd_published_at":null,"cwe_ids":["CWE-400","CWE-770"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/DataDog/dd-trace-java/security/advisories/GHSA-74xj-wh4w-vqxc"},{"type":"PACKAGE","url":"https://github.com/DataDog/dd-trace-java"}],"affected":[{"package":{"name":"com.datadoghq:dd-java-agent","ecosystem":"Maven","purl":"pkg:maven/com.datadoghq/dd-java-agent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.62.0"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.1.0","0.1.1","0.1.2","0.10.0","0.100.0","0.101.0","0.102.0","0.103.0","0.104.0","0.105.0","0.106.0","0.107.0","0.107.1","0.108.0","0.108.1","0.108.2","0.109.0","0.109.1","0.11.0","0.110.0","0.111.0","0.112.0","0.113.0","0.114.0","0.115.0","0.115.1","0.12.0","0.13.0","0.14.0","0.15.0","0.16.0","0.17.0","0.18.0","0.19.0","0.2.0","0.2.1","0.2.10","0.2.11","0.2.12","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","0.2.8","0.2.9","0.20.0","0.21.0","0.21.1","0.22.0","0.23.0","0.24.0","0.24.1","0.25.0","0.26.0","0.26.1","0.26.2","0.27.0","0.28.0","0.29.0","0.29.1","0.3.0","0.3.0.RC1","0.3.0.RC2","0.3.1","0.3.2","0.3.3","0.30.0","0.31.0","0.31.1","0.31.2","0.32.0","0.33.0","0.34.0","0.35.0","0.36.0","0.37.0","0.38.0","0.39.0","0.4.0","0.4.1","0.40.0","0.41.0","0.42.0","0.43.0","0.44.0","0.45.0","0.46.0","0.47.0","0.48.0","0.49.0","0.5.0","0.50.0","0.51.0","0.52.0","0.53.0","0.54.0","0.55.0","0.55.1","0.56.0","0.57.0","0.58.0","0.59.0","0.6.0","0.60.0","0.60.1","0.61.0","0.62.0","0.63.0","0.64.0","0.65.0","0.66.0","0.67.0","0.68.0","0.69.0","0.7.0","0.70.0","0.71.0","0.72.0","0.73.0","0.74.0","0.74.1","0.75.0","0.76.0","0.76.1","0.77.0","0.78.0","0.78.1","0.78.2","0.78.3","0.79.0","0.8.0","0.80.0","0.81.0","0.81.1","0.82.0","0.83.0","0.83.1","0.83.2","0.84.0","0.85.0","0.86.0","0.87.0","0.88.0","0.89.0","0.9.0","0.90.0","0.91.0","0.92.0","0.93.0","0.94.0","0.94.1","0.95.0","0.95.1","0.96.0","0.97.0","0.98.0","0.98.1","0.99.0","1.0.0","1.0.1","1.1.0","1.1.1","1.1.3","1.1.4","1.10.0","1.10.1","1.11.0","1.11.1","1.11.2","1.12.0","1.12.1","1.13.0","1.14.0","1.15.0","1.15.1","1.15.3","1.16.0","1.16.1","1.16.2","1.16.3","1.17.0","1.18.0","1.18.1","1.18.2","1.18.3","1.19.0","1.19.1","1.19.2","1.19.3","1.2.0","1.20.0","1.20.1","1.21.0","1.22.0","1.23.0","1.24.0","1.24.1","1.24.2","1.25.1","1.26.0","1.26.1","1.27.0","1.28.0","1.28.0-RC2","1.28.0-RC3","1.29.0","1.3.0","1.30.0","1.30.1","1.31.0","1.31.1","1.31.2","1.32.0","1.33.0","1.34.0","1.35.0","1.35.2","1.36.0","1.37.0","1.37.1","1.38.0","1.38.1","1.39.0","1.39.1","1.4.0","1.40.0","1.40.1","1.40.2","1.41.0","1.41.1","1.41.2","1.42.0","1.42.1","1.42.2","1.43.0","1.44.0","1.44.1","1.45.0","1.45.1","1.45.2","1.46.0","1.46.1","1.47.0","1.47.1","1.47.2","1.47.3","1.48.0","1.48.1","1.48.2","1.49.0","1.5.0","1.50.0","1.50.1","1.51.0","1.51.1","1.51.2","1.52.0","1.52.1","1.53.0","1.54.0","1.55.0","1.56.0","1.56.1","1.56.2","1.56.3","1.57.0","1.58.0","1.58.1","1.58.2","1.59.0","1.6.0","1.60.0","1.60.1","1.60.2","1.60.3","1.60.4","1.61.0","1.61.1","1.7.0","1.8.0","1.8.3","1.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-74xj-wh4w-vqxc/GHSA-74xj-wh4w-vqxc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}