Intel

AIKIDO-2026-10708

datadog/dd-trace is vulnerable to Use After Free

Use After Free Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 4, 2026

55

Medium Risk

This Affects:

phpdatadog/dd-trace
0.0.1 - 1.18.0
Fixed in 1.19.0
Are you affected? Scan for Free

TL;DR

A ZTS (thread-safety) race condition existed in AppSec INI/process-tag handling where shared refcounted Zend strings could be accessed by multiple threads at the same time. This concurrency issue made the extension vulnerable to use-after-free crashes under load, as well as related shutdown hangs and early logging initialization problems.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

datadog/dd-trace is vulnerable to Use After Free in versions 0.0.1 - 1.18.0.

How to fix this

Upgrade the datadog/dd-trace library to the patch version.