


Perceptive Security
SOC/SIEM Consultancy

dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses t…
Published:
28 augustus 2026 om 00:00:00
Alert date:
28 augustus 2026 om 23:18:31
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
CVE-2026-54788 affects dd-trace-rs, Datadog's application performance monitoring library for Rust. Versions 0.1.0 through 0.3.2 are vulnerable to a denial-of-service attack via the W3C tracestate header parsing logic. The vulnerable code in tracecontext.rs collects all semicolon-separated key-value pairs from the Datadog dd=... vendor entry into a HashMap with no limit on pair count or entry size. Since tracecontext extraction is enabled by default, a remote unauthenticated attacker can craft an arbitrarily large dd=... header value to force excessive CPU and memory consumption on each request. This can effectively bring down any instrumented Rust network service. The vulnerability has been patched in version 0.3.3 of the datadog-opentelemetry crate.
Technical details
Mitigation steps:
Affected products:
dd-trace-rs
datadog-opentelemetry
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54788
https://github.com/DataDog/dd-trace-rs/commit/77c5d185c71d0ea8103da0e6cf4cd50677ffacd2
https://github.com/DataDog/dd-trace-rs/pull/218
https://github.com/DataDog/dd-trace-rs/releases/tag/datadog-opentelemetry-v0.3.3
https://github.com/DataDog/dd-trace-rs/security/advisories/GHSA-gpwf-4h98-v82q
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
