VulnSea

DataDog has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 4. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-770 (6) and CWE-400 (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
6 prev 0

Weakness classes

Products

  • Datadog.Trace 1
  • dd-trace-cpp 1
  • dd-trace-java 1
  • dd-trace-php 1
  • dd-trace-rb 1
  • github.com/DataDog/dd-trace-go 1
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

DataDog vulnerabilities

CVEs affecting DataDog, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-50275High· 7.5
5d ago

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers.c parses incoming W3C baggage HTTP headers without enforc…

TwilightDataDog · dd-trace-phpEPSS 0.48%via NVD
CVE-2026-50277High· 7.5
5d ago

dd-trace-cpp is the Datadog distributed tracing library for C++

dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on the extraction path, even tho…

TwilightDataDog · dd-trace-cppEPSS 0.56%via NVD
CVE-2026-50270High· 7.5
1w ago

dd-trace-java is a Datadog APM client for Java

dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply…

TwilightDataDog · dd-trace-javaEPSS 0.56%via NVD
CVE-2026-50276High· 7.5
1w ago

dd-trace-rb is Datadog's client library for Ruby

dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits app…

TwilightDataDog · dd-trace-rbEPSS 0.76%via NVD
CVE-2026-50273High· 7.5
2mo ago

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

TwilightDatadog · Datadog.TraceEPSS 0.79%via GHSA
CVE-2026-50274High· 7.5
2mo ago

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

TwilightDataDog · github.com/DataDog/dd-trace-goEPSS 0.79%via OSV
DataDog vulnerabilities (CVEs) · VulnSea