CVE-2026-50275

Source
https://cve.org/CVERecord?id=CVE-2026-50275
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50275.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-50275
Aliases
  • GHSA-phwx-ww2p-cv9v
Published
2026-09-17T20:04:26Z
Modified
2026-09-20T14:24:09Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Datadog PHP Tracer: Improper parsing of W3C baggage headers may lead to DoS
Details

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers.c parses incoming W3C baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES. A remote unauthenticated client can send an arbitrarily large number of comma-separated key-value pairs or a single oversized value, causing the tracer to allocate hash-map entries and consume unbounded CPU and memory on each request. Baggage extraction is enabled by default in most affected deployments unless baggage is removed from DD_TRACE_PROPAGATION_STYLE or DD_TRACE_PROPAGATION_STYLE_EXTRACT. This issue is fixed in version 1.19.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-770"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50275.json"
}
References

Affected packages

Git / github.com/datadog/dd-trace-php

Affected ranges

Type
GIT
Repo
https://github.com/datadog/dd-trace-php
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.19.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.15.0
0.15.1
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.19.1
0.2.0
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.28.1
0.29.0
0.3.0
0.3.1
0.39.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.8.0
0.8.1
0.87.0
0.87.1
0.89.0
0.9.0
0.9.1
0.90.0
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.*
1.0.0
1.0.0beta1
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.19.0
1.19.1
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.7.0
1.8.0
v0.*
v0.1.0
v0.1.1
v0.1.2
v0.2.0
v0.2.1
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v0.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50275.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "308832864153849595563629088208305002404",
            "length": 708
        },
        "id": "CVE-2026-50275-35861aac",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/43072ccafe55a5dbdfba75a42bf316b4150ae1e5",
        "target": {
            "file": "ext/ddtrace.c",
            "function": "ddtrace_startup"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "47776930390706990498281690415703184689",
            "length": 6291
        },
        "id": "CVE-2026-50275-3af61f7b",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/2f7987eb02e306bb62bce8ec4152dece68112f51",
        "target": {
            "file": "ext/telemetry.c",
            "function": "ddtrace_telemetry_finalize"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "139507486884425511773975124969602934272",
            "length": 94
        },
        "id": "CVE-2026-50275-561b41ab",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/2f7987eb02e306bb62bce8ec4152dece68112f51",
        "target": {
            "file": "ext/ddtrace.c",
            "function": "ddtrace_shutdown"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "235395358532456694738567024743457909924",
                "335772219290718447923997206029173391154",
                "247135620481195339887006673740251937533",
                "68183186049888403516320261893440338934",
                "246526392674907930195977607240096448699",
                "207403566292941612736970975718266693828",
                "7885670634225884789064670637144546778",
                "199849801643841087235385110226844150898"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50275-5671a384",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/43072ccafe55a5dbdfba75a42bf316b4150ae1e5",
        "target": {
            "file": "ext/telemetry.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "154079589367803434713883527153606971983",
                "12150844513485094287176056453006467368",
                "102409736461359025608156070728189409880",
                "286078718980334209502185361446202987712",
                "327107534192961185262237728875819136626",
                "287794035455920436735875734954462292285",
                "114549944343539958164779623002052106127",
                "271042082927950005396444758806624918862",
                "236959974079302930321867988692347489783",
                "250871928880341428472949215973097713739",
                "179156292992366648854851553967824099940",
                "144430241241060183563301690853654717797",
                "31345724862258272232409114864097562957",
                "200486610045718166518380334125214163574",
                "178353503647215833956261182376142093262",
                "212040787660604699631271049200710535525",
                "2116820899202315144491960217489155145",
                "334807931052943123393730477190434869726",
                "199889907164539253370829969650526706077",
                "249472875117817306004351494620763432360",
                "188551436732772007035844140477624836082",
                "135497544953894159807600664466149140753",
                "113629866679805494282188515558624920761",
                "285092984661979979932466343633785621906",
                "41120530249058337186506122826111949640",
                "33310184715639964298039312682116743509",
                "117108280787153250856840354636519932343",
                "248816069653256296495290024319173950178",
                "120449959923495968328021300486632079599",
                "118005082566273726965680157817707075684",
                "159797617065138394944112506583516528682",
                "9079675226267360391734441080273844096",
                "20125226527549772481293086060361140521"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50275-65e322e1",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/2f7987eb02e306bb62bce8ec4152dece68112f51",
        "target": {
            "file": "ext/distributed_tracing_headers.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "65052568069756989821175921028264765782",
            "length": 4136
        },
        "id": "CVE-2026-50275-67f4f4b6",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/43072ccafe55a5dbdfba75a42bf316b4150ae1e5",
        "target": {
            "file": "ext/distributed_tracing_headers.c",
            "function": "ddtrace_read_distributed_tracing_ids_tracecontext"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "154079589367803434713883527153606971983",
                "12150844513485094287176056453006467368",
                "102409736461359025608156070728189409880",
                "286078718980334209502185361446202987712",
                "327107534192961185262237728875819136626",
                "287794035455920436735875734954462292285",
                "114549944343539958164779623002052106127",
                "271042082927950005396444758806624918862",
                "236959974079302930321867988692347489783",
                "250871928880341428472949215973097713739",
                "179156292992366648854851553967824099940",
                "144430241241060183563301690853654717797",
                "31345724862258272232409114864097562957",
                "200486610045718166518380334125214163574",
                "178353503647215833956261182376142093262",
                "212040787660604699631271049200710535525",
                "2116820899202315144491960217489155145",
                "334807931052943123393730477190434869726",
                "199889907164539253370829969650526706077",
                "249472875117817306004351494620763432360",
                "188551436732772007035844140477624836082",
                "135497544953894159807600664466149140753",
                "113629866679805494282188515558624920761",
                "285092984661979979932466343633785621906",
                "41120530249058337186506122826111949640",
                "33310184715639964298039312682116743509",
                "117108280787153250856840354636519932343",
                "248816069653256296495290024319173950178",
                "120449959923495968328021300486632079599",
                "118005082566273726965680157817707075684",
                "159797617065138394944112506583516528682",
                "9079675226267360391734441080273844096",
                "20125226527549772481293086060361140521"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50275-6fdb1417",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/43072ccafe55a5dbdfba75a42bf316b4150ae1e5",
        "target": {
            "file": "ext/distributed_tracing_headers.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "189752570563556244023206261718321470701",
                "211715101787712519506444343996946740673",
                "140754727526259723433492821446133965225",
                "116581566476179891319101473965031666864",
                "301737922618118983450490416857161515047",
                "144019995571990562703958545313992939598",
                "94779372948957953834800576770151065778",
                "244435831065413600054712818455149279442",
                "271490893676424687996631618635805173680",
                "10293094265668112781433045731389954675"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50275-774c84e0",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/2f7987eb02e306bb62bce8ec4152dece68112f51",
        "target": {
            "file": "ext/ddtrace.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "306639319744774973543876423638420853065",
                "38834241192858231518106119766975649138",
                "5511381996783781191202852953456592525",
                "84508964504416113185130607813751234020"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50275-7841f3fa",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/2f7987eb02e306bb62bce8ec4152dece68112f51",
        "target": {
            "file": "ext/ddtrace.h"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "123671435113880466098326176576940362292",
            "length": 415
        },
        "id": "CVE-2026-50275-8786808c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/43072ccafe55a5dbdfba75a42bf316b4150ae1e5",
        "target": {
            "file": "ext/telemetry.c",
            "function": "ddtrace_telemetry_rinit"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "139507486884425511773975124969602934272",
            "length": 94
        },
        "id": "CVE-2026-50275-948b7b92",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/43072ccafe55a5dbdfba75a42bf316b4150ae1e5",
        "target": {
            "file": "ext/ddtrace.c",
            "function": "ddtrace_shutdown"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "58434076323404229580023358976467875427",
            "length": 1996
        },
        "id": "CVE-2026-50275-96e6495d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/43072ccafe55a5dbdfba75a42bf316b4150ae1e5",
        "target": {
            "file": "ext/distributed_tracing_headers.c",
            "function": "ddtrace_deserialize_baggage"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "189752570563556244023206261718321470701",
                "211715101787712519506444343996946740673",
                "140754727526259723433492821446133965225",
                "116581566476179891319101473965031666864",
                "301737922618118983450490416857161515047",
                "144019995571990562703958545313992939598",
                "94779372948957953834800576770151065778",
                "244435831065413600054712818455149279442",
                "271490893676424687996631618635805173680",
                "10293094265668112781433045731389954675"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50275-97c24cd6",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/43072ccafe55a5dbdfba75a42bf316b4150ae1e5",
        "target": {
            "file": "ext/ddtrace.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "306639319744774973543876423638420853065",
                "38834241192858231518106119766975649138",
                "5511381996783781191202852953456592525",
                "84508964504416113185130607813751234020"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50275-b232a2dd",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/43072ccafe55a5dbdfba75a42bf316b4150ae1e5",
        "target": {
            "file": "ext/ddtrace.h"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "47776930390706990498281690415703184689",
            "length": 6291
        },
        "id": "CVE-2026-50275-b809aff3",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/43072ccafe55a5dbdfba75a42bf316b4150ae1e5",
        "target": {
            "file": "ext/telemetry.c",
            "function": "ddtrace_telemetry_finalize"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "308832864153849595563629088208305002404",
            "length": 708
        },
        "id": "CVE-2026-50275-cf156a9a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/2f7987eb02e306bb62bce8ec4152dece68112f51",
        "target": {
            "file": "ext/ddtrace.c",
            "function": "ddtrace_startup"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "65052568069756989821175921028264765782",
            "length": 4136
        },
        "id": "CVE-2026-50275-f1ddfd73",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/2f7987eb02e306bb62bce8ec4152dece68112f51",
        "target": {
            "file": "ext/distributed_tracing_headers.c",
            "function": "ddtrace_read_distributed_tracing_ids_tracecontext"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "58434076323404229580023358976467875427",
            "length": 1996
        },
        "id": "CVE-2026-50275-f4fe04d0",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/2f7987eb02e306bb62bce8ec4152dece68112f51",
        "target": {
            "file": "ext/distributed_tracing_headers.c",
            "function": "ddtrace_deserialize_baggage"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "123671435113880466098326176576940362292",
            "length": 415
        },
        "id": "CVE-2026-50275-fb38bdf7",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/2f7987eb02e306bb62bce8ec4152dece68112f51",
        "target": {
            "file": "ext/telemetry.c",
            "function": "ddtrace_telemetry_rinit"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "235395358532456694738567024743457909924",
                "335772219290718447923997206029173391154",
                "247135620481195339887006673740251937533",
                "68183186049888403516320261893440338934",
                "246526392674907930195977607240096448699",
                "207403566292941612736970975718266693828",
                "7885670634225884789064670637144546778",
                "199849801643841087235385110226844150898"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50275-fe6daf73",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/datadog/dd-trace-php/commit/2f7987eb02e306bb62bce8ec4152dece68112f51",
        "target": {
            "file": "ext/telemetry.c"
        }
    }
]
vanir_signatures_modified
"2026-09-20T14:24:09Z"