CVE-2026-54788
dd-trace-rs: Unbounded W3C tracestate parsing may lead to DoS
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in the Datadog dd=... vendor entry into a HashMap without enforcing a pair count or entry size limit. Because tracecontext extraction is enabled by default, a remote unauthenticated attacker can send an arbitrarily large dd=... entry and force excessive CPU and memory consumption for each request, causing denial of service in an instrumented network service. This vulnerability is fixed in 0.3.3.
| CWE | CWE-770 |
| Vendor | datadog |
| Product | dd-trace-rs |
| Published | Aug 28, 2026 |
Get instant alerts for datadog dd-trace-rs
Be the first to know when new high vulnerabilities affecting datadog dd-trace-rs are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H