Intel

AIKIDO-2025-10569

github.com/Datadog/dd-trace-go/contrib/google.golang.org/grpc/v2 is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 20, 2025

35

Low Risk

Are you affected? Scan for Free

TL;DR

Affected versions of the github.com/Datadog/dd-trace-go/contrib/google.golang.org/grpc/v2 package may leak sensitive information through log files in multiple parts of the codebase, exposing confidential data to unauthorized access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/Datadog/dd-trace-go/contrib/google.golang.org/grpc/v2 is vulnerable to Insertion of Sensitive Information into Log File in versions 2.0.0 - 2.2.1.

How to fix this

Upgrade github.com/Datadog/dd-trace-go/contrib/google.golang.org/grpc/v2 to the patch version.