Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

DataDog — Vulnerabilities & Security Advisories 26

Browse all 26 CVE security advisories affecting DataDog. AI-powered Chinese analysis, POCs, and references for each vulnerability.

DataDog provides cloud-scale monitoring and security analytics for infrastructure and applications. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and authentication flaws. While no major public security incidents have been widely reported, the platform maintains a moderate CVE count with 9 records to date. Security characteristics include its extensive agent-based architecture, which requires careful permission management, and its cloud-native integrations that expand potential attack surfaces. The platform's complexity increases exposure to misconfiguration risks, though its security team typically addresses reported vulnerabilities through timely patches.

CVE ID Title CVSS Severity Published
CVE-2026-50277 dd-trace-cpp: Improper parsing of W3C baggage headers may lead to DoS — dd-trace-cpp CWE-770 7.5 High 2026-09-17
CVE-2026-50275 Datadog PHP Tracer: Improper parsing of W3C baggage headers may lead to DoS — dd-trace-php CWE-770 7.5 High 2026-09-17
CVE-2026-50276 dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS — dd-trace-rb CWE-770 7.5 High 2026-09-14
CVE-2026-50270 dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS — dd-trace-java CWE-770 7.5 High 2026-09-14
CVE-2026-54788 dd-trace-rs: Unbounded W3C tracestate parsing may lead to DoS — dd-trace-rs CWE-770 7.5 High 2026-08-28
CVE-2026-44964 Datadog 服务端请求伪造漏洞 — Android App CWE-441 - - 2026-08-07
CVE-2026-44965 Datadog 权限许可和访问控制问题漏洞 — Android App CWE-926 - - 2026-08-07
CVE-2026-47364 Datadog 信息泄露漏洞 — Android App CWE-200 - - 2026-08-07
CVE-2026-47363 Datadog 权限许可和访问控制问题漏洞 — Android App CWE-926 - - 2026-08-07
CVE-2026-47361 Datadog 权限许可和访问控制问题漏洞 — Android App CWE-926 - - 2026-08-07
CVE-2026-47362 Datadog 授权问题漏洞 — Android App CWE-922 - - 2026-08-07
CVE-2026-50271 dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS — dd-trace-py CWE-770 7.5 High 2026-07-17
CVE-2026-50274 dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS — dd-trace-go CWE-770 7.5 High 2026-07-17
CVE-2026-50272 dd-trace: Improper parsing of W3C baggage headers may lead to DoS — dd-trace-js CWE-770 7.5 High 2026-07-17
CVE-2026-50273 Datadog .NET Tracer: Improper parsing of W3C baggage headers may lead to DoS — dd-trace-dotnet CWE-770 7.5 High 2026-07-17
CVE-2026-44971 GuardDog: Blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltration — guarddog CWE-918 8.2 High 2026-05-27
CVE-2026-44972 GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content — guarddog CWE-116 5.0 Medium 2026-05-27
CVE-2026-33728 dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code execution — dd-trace-java CWE-502 8.1 - 2026-03-27
CVE-2026-22871 GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE — guarddog CWE-22 9.8AI Critical AI 2026-01-13
CVE-2026-22870 GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS — guarddog CWE-409 7.5AI High AI 2026-01-13
CVE-2025-61667 Datadog Linux Host Agent affected by local privilege escalation due to insufficient pycache permissions — datadog-agent CWE-276 7.8 - 2025-11-12
CVE-2024-38525 dd-trace-cpp malformed unicode header values may cause crash — dd-trace-cpp CWE-20 7.5 High 2024-06-28
CVE-2023-38704 import-in-the-middle allows unsanitized user controlled input in module generation — import-in-the-middle CWE-20 8.1 High 2023-08-07
CVE-2022-23531 Arbitrary file write when scanning a specially-crafted local PyPI package — guarddog CWE-23 5.8 Medium 2022-12-16
CVE-2022-23530 GuardDog vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI package — guarddog CWE-22 5.8 Medium 2022-12-16
CVE-2021-21331 DataDog API Client contains a Local Information Disclosure Vulnerability — datadog-api-client-java CWE-379 3.0 Low 2021-03-03

This page lists every published CVE security advisory associated with DataDog. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.