AI and data stack advisories

Severe, 6 weeks1824Projects321

1824 severe, 6 weeks · 321 projects

DatadogGHSA-9x8v-5f43-c55r

ReDOS in URL query string obfuscation

Datadog

Published Oct 8, 2026

High8.7
Fix: upgrade to 1.67.1 or later (2 fixed versions below)
GitHub advisory

Summary

A regular expression used to obfuscate URL query strings can consume excessive CPU when processing certain attacker-controlled input. This can stall request processing and cause denial of service in applications using affected HTTP tracing integrations.

Details

The default query-string obfuscation pattern can exhibit excessive backtracking. The pattern is applied synchronously when recording HTTP URL metadata, allowing query-string processing to occupy application resources for an extended period.

The obfuscation runs on the background thread that serializes traces, not on the request thread. The impact is high CPU usage and dropped traces, not request latency. As a workaround, set DD_HTTP_SERVER_TAG_QUERY_STRING=false before starting the application.

Proof of concept

Detailed triggering inputs and reproduction steps are omitted from this advisory. The patched version includes regression coverage for the affected behavior.

Impact

Regular expression denial of service (ReDoS) affecting applications that process attacker-controlled URL query strings through the vulnerable obfuscation pattern. Successful exploitation can cause excessive CPU consumption, prolonged request latency, and service unavailability.

The vulnerable processing is enabled by default for affected HTTP integrations that include query strings in URL span tags.

Affected versions

PackageAffectedFixed in
com.datadoghq:dd-java-agent
Maven
>= 1.67.0, < 1.67.11.67.1
com.datadoghq:dd-trace-ot
Maven
>= 1.67.0, < 1.67.11.67.1
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)

More Datadog advisories

All Datadog