CVE-2026-54788: Datadog Dd-Trace-RS
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in the Datadog dd=... vendor entry into a HashMap without enforcing a pair count or entry size limit. Because tracecontext extraction is enabled by default, a remote unauthenticated attacker can send an arbitrarily large dd=... entry and force excessive CPU and memory consumption for each request, causing denial of service in an instrumented network service. This vulnerability is fixed in 0.3.3.
Affected products
- Datadog Dd-Trace-RS: from 0.1.0, before 0.3.3 (fixed in 0.3.3)
Published 2026-08-28. Last modified 2026-09-09.