HIGH 7.5 NVD
CVE-2026-54788
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses t
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in the Datadog dd=... vendor entry into a HashMap without enforcing a pair count or entry size limit. Because tracecontext extraction is enabled by default, a remote unauthenticated attacker can send an arbitrarily large dd=... entry and force excessive CPU and memory consumption for each request, causing denial of service in an instrumented network service. This vulnerability is fixed in 0.3.3.
References
- https://github.com/DataDog/dd-trace-rs/commit/77c5d185c71d0ea8103da0e6cf4cd50677ffacd2
- https://github.com/DataDog/dd-trace-rs/pull/218
- https://github.com/DataDog/dd-trace-rs/releases/tag/datadog-opentelemetry-v0.3.3
- https://github.com/DataDog/dd-trace-rs/security/advisories/GHSA-gpwf-4h98-v82q
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-08-28 via NVD.
vulnfeed aggregates 11493 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.