Intel

AIKIDO-2024-10338

datadog/dd-trace is vulnerable to Denial of Service (DoS) due to Memory Leak or Race Condition

Denial of Service (DoS) due to Memory Leak or Race Condition Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

49

Medium Risk

This Affects:

phpdatadog/dd-trace
0.1.0 - 1.3.2
Fixed in 1.4.0

TL;DR

Affected versions of the package are vulnerable to denial of service Denial of Service (DoS) due to memory leaks or race conditions in multiple areas of the codebase. These issues can lead to resource exhaustion or unpredictable behavior, potentially causing the application to crash or become unresponsive under certain conditions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

datadog/dd-trace is vulnerable to Denial of Service (DoS) due to Memory Leak or Race Condition in versions 0.1.0 - 1.3.2.

How to fix this

Upgrade the datadog/dd-trace library to the patch version.