dd-trace is vulnerable to Denial of Service (DoS)
59
Medium Risk
The tracer's resizable msgpack write buffer grows its backing allocation without any upper bound while serializing trace payloads. A single pathological span, such as a multi-megabyte stack trace or an oversized unsanitized meta tag, can force the buffer to grow until the allocation fails and crashes the host process. Because span data can be derived from attacker-influenced input, an instrumented application can be driven to out-of-memory termination. The fix caps buffer growth at the 50 MiB agent intake limit and throws a tagged ERR_MSGPACK_CHUNK_OVERFLOW overflow error so oversized payloads are dropped instead of exhausting memory.
You are affected if you are using a version that falls within the vulnerable range.
dd-trace is vulnerable to Denial of Service (DoS) in versions 5.29.0 - 5.112.0.
Upgrade the dd-trace library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant