{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/datadog-opentelemetry-0.1.0---0.3.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:datadog:datadog-opentelemetry:*:*:*:*:*:rust:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-54788"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["datadog-opentelemetry (0.1.0 - 0.3.2)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","rust","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Datadog"],"content_html":"\u003cp\u003eThe datadog-opentelemetry Rust library (versions 0.1.0 through 0.3.2) contains a vulnerability in its implementation of W3C Trace Context propagation. The tracer performs unbounded parsing of the \u003ccode\u003etracestate\u003c/code\u003e header, specifically when processing the Datadog vendor entry (\u003ccode\u003edd=...\u003c/code\u003e). This entry contains semicolon-separated key:value pairs which the library stores in a hash map without enforcing a size limit on the input or the resulting structure.\u003c/p\u003e\n\u003cp\u003eA remote, unauthenticated attacker can exploit this by sending HTTP requests with a maliciously crafted \u003ccode\u003etracestate\u003c/code\u003e header containing an arbitrarily large number of key:value pairs or an excessively large string. Because \u003ccode\u003etracecontext\u003c/code\u003e extraction is enabled by default in affected tracers, services using this library are exposed to resource exhaustion. The resulting CPU and memory consumption can lead to a Denial of Service (DoS) for the instrumented application. This issue is tracked as CVE-2026-54788.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to a remote Denial of Service (DoS) by saturating server CPU and memory. Any internet-facing service instrumented with the vulnerable library versions is at risk, potentially causing service outages or significant performance degradation across affected microservices and backend systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003edd-trace-rs\u003c/code\u003e to version 0.3.3 or later to apply the necessary input parsing bounds.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, disable \u003ccode\u003etracecontext\u003c/code\u003e extraction by setting the \u003ccode\u003eDD_TRACE_PROPAGATION_STYLE_EXTRACT\u003c/code\u003e environment variable to a value that excludes \u003ccode\u003etracecontext\u003c/code\u003e, such as \u003ccode\u003edatadog\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eImplement header size restrictions at the infrastructure level by configuring upstream proxies or web servers to reject requests with excessively large \u003ccode\u003etracestate\u003c/code\u003e headers.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-29T03:14:08Z","date_published":"2026-08-29T03:14:08Z","id":"https://feed.craftedsignal.io/briefs/2026-08-datadog-opentelemetry-dos/","summary":"The datadog-opentelemetry Rust library is vulnerable to a remote denial-of-service attack due to unbounded parsing of the W3C tracestate header, allowing unauthenticated attackers to exhaust CPU and memory resources.","title":"Unbounded W3C Tracestate Parsing in datadog-opentelemetry","url":"https://feed.craftedsignal.io/briefs/2026-08-datadog-opentelemetry-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Datadog-Opentelemetry (0.1.0 - 0.3.2)","version":"https://jsonfeed.org/version/1.1"}