ReDOS in URL query string obfuscation
Summary
A regular expression used to obfuscate URL query strings can consume excessive CPU when processing certain attacker-controlled input. This can stall request processing and cause denial of service in applications using affected HTTP tracing integrations.
Details
The default query-string obfuscation pattern can exhibit excessive backtracking. The pattern is applied synchronously when recording HTTP URL metadata, allowing query-string processing to occupy application resources for an extended period.
The obfuscation runs on the background thread that serializes traces, not on the request thread. The impact is high CPU usage and dropped traces, not request latency. As a workaround, set DD_HTTP_SERVER_TAG_QUERY_STRING=false before starting the application.
Proof of concept
Detailed triggering inputs and reproduction steps are omitted from this advisory. The patched version includes regression coverage for the affected behavior.
Impact
Regular expression denial of service (ReDoS) affecting applications that process attacker-controlled URL query strings through the vulnerable obfuscation pattern. Successful exploitation can cause excessive CPU consumption, prolonged request latency, and service unavailability.
The vulnerable processing is enabled by default for affected HTTP integrations that include query strings in URL span tags.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| com.datadoghq:dd-java-agent Maven | >= 1.67.0, < 1.67.1 | 1.67.1 |
| com.datadoghq:dd-trace-ot Maven | >= 1.67.0, < 1.67.1 | 1.67.1 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)