datadog/dd-trace is vulnerable to Use After Free
55
Medium Risk
A ZTS (thread-safety) race condition existed in AppSec INI/process-tag handling where shared refcounted Zend strings could be accessed by multiple threads at the same time. This concurrency issue made the extension vulnerable to use-after-free crashes under load, as well as related shutdown hangs and early logging initialization problems.
You are affected if you are using a version that falls within the vulnerable range.
datadog/dd-trace is vulnerable to Use After Free in versions 0.0.1 - 1.18.0.
Upgrade the datadog/dd-trace library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant