VDB
Sign up
HIGH7.5

GHSA-gpwf-4h98-v82q

datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS

Details

### Impact Datadog tracing libraries that implement W3C Trace Context (`tracecontext`) propagation parse the incoming `tracestate` header without enforcing a size cap on the Datadog vendor entry (`dd=...`). The `dd=` value contains semicolon-separated `key:value` pairs, and the parser allocates a hash-map entry for each pair. A remote, unauthenticated attacker can send a `tracestate` header whose `dd=` member is arbitrarily large (or contains an arbitrarily large number of pairs), forcing unbounded CPU and memory consumption per request and enabling a remote Denial of Service. `tracecontext` extraction is enabled by default in affected tracers, so any internet-facing service instrumented with an affected version is exposed unless `tracecontext` has been explicitly removed from the propagation style configuration.

### Patches This is resolved in version 0.3.3 and later of the `dd-trace-rs` library.

### Workarounds If you cannot upgrade immediately: 1. Disable `tracecontext` extraction by setting `DD_TRACE_PROPAGATION_STYLE_EXTRACT` to a value that does not include `tracecontext` (for example, `datadog`). 2. Cap the maximum HTTP request header size at an upstream proxy or web server.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/datadog-opentelemetry
Introduced in: 0.1.0Fixed in: 0.3.3

Upgrade datadog-opentelemetry to 0.3.3 or newer (ecosystem crates.io).

References