dd-trace: Improper parsing of W3C baggage headers may lead to DoS
Description
dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on extraction. A remote, unauthenticated attacker can send a request whose baggage header contains an arbitrarily large number of comma-separated key-value pairs, or a single very large value, causing unbounded CPU and memory consumption and enabling a remote denial of service against any HTTP service with baggage propagation enabled. This issue is fixed in version 5.100.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dd-tracenpm | < 5.100.0 | 5.100.0 |
Affected products
6- Range: <5.100.0
- Range: <5.100.0
- osv-coords4 versionspkg:apk/chainguard/langfuse-2pkg:apk/chainguard/langfuse-2-workerpkg:apk/chainguard/langfuse-fips-2pkg:apk/chainguard/langfuse-fips-2-worker
< 2.95.12-r36+ 3 more
- (no CPE)range: < 2.95.12-r36
- (no CPE)range: < 2.95.12-r36
- (no CPE)range: < 2.95.12-r39
- (no CPE)range: < 2.95.12-r39
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-wxqq-gcq8-c443ghsaADVISORY
- github.com/DataDog/dd-trace-js/commit/a7d4c0da05f67cde05a99272b725a317c461d0e6mitrex_refsource_MISC
- github.com/DataDog/dd-trace-js/pull/8255mitrex_refsource_MISC
- github.com/DataDog/dd-trace-js/releases/tag/v5.100.0mitrex_refsource_MISC
- github.com/DataDog/dd-trace-js/security/advisories/GHSA-wxqq-gcq8-c443ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.