DataDog has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 4. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-770 (6) and CWE-400 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Products
- Datadog.Trace 1
- dd-trace-cpp 1
- dd-trace-java 1
- dd-trace-php 1
- dd-trace-rb 1
- github.com/DataDog/dd-trace-go 1
Worst active — by depth score
CVE-2026-50277High· 7.5dd-trace-cpp is the Datadog distributed tracing library for C++41CVE-2026-50275High· 7.5The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP41CVE-2026-50276High· 7.5dd-trace-rb is Datadog's client library for Ruby41CVE-2026-50270High· 7.5dd-trace-java is a Datadog APM client for Java41CVE-2026-50274High· 7.5dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS41
DataDog vulnerabilities
CVEs affecting DataDog, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-50275High· 7.5The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP
The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers.c parses incoming W3C baggage HTTP headers without enforc…
CVE-2026-50277High· 7.5dd-trace-cpp is the Datadog distributed tracing library for C++
dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on the extraction path, even tho…
CVE-2026-50270High· 7.5dd-trace-java is a Datadog APM client for Java
dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply…
CVE-2026-50276High· 7.5dd-trace-rb is Datadog's client library for Ruby
dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits app…
CVE-2026-50273High· 7.5dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-50274High· 7.5dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS