THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gpwf-4h98-v82q (high) — datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS

[GHSA] GHSA-gpwf-4h98-v82q (high) — datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS

medgithub_advisoriesPublished 2026-08-28

GHSA-gpwf-4h98-v82q Severity: high CVE: CVE-2026-54788

datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS

### Impact Datadog tracing libraries that implement W3C Trace Context (`tracecontext`) propagation parse the incoming `tracestate` header without enforcing a size cap on the Datadog vendor entry (`dd=...`). The `dd=` value contains semicolon-separated `key:value`

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gpwf-4h98-v82q