dd-trace is vulnerable to Prototype Pollution
41
Medium Risk
Affected versions of this package contain a prototype pollution flaw in GraphQL instrumentation where a crafted query using __proto__ as a field name can mutate Object.prototype through resolver-span tracking, and may also trigger tracing/serialisation failures that disrupt normal execution. An attacker able to send malicious GraphQL queries could exploit this by injecting __proto__ fields to poison shared object state across the process, causing unpredictable behavior, application errors, or denial of service through instrumentation crashes and trace submission failures.
You are affected if you are using a version that falls within the vulnerable range.
dd-trace is vulnerable to Prototype Pollution in versions 2.11.0 - 5.96.0.
Upgrade the dd-trace library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant