AI and data stack advisories

Severe, 6 weeks2048Projects319

2048 severe, 6 weeks · 319 projects

DatadogGHSA-x94g-w73q-hpcw

ReDOS in URL query string obfuscation

Datadog

Published Oct 8, 2026

High8.7
Fix: upgrade to 5.131.1 or later (2 fixed versions below)
GitHub advisory

Summary

A regular expression used to obfuscate URL query strings can consume excessive CPU when processing certain attacker-controlled input. This can stall request processing and cause denial of service in applications using affected HTTP tracing integrations.

Details

The default query-string obfuscation pattern can exhibit excessive backtracking. The pattern is applied synchronously when recording HTTP URL metadata, allowing query-string processing to occupy application resources for an extended period.

As a workaround, set DD_TRACE_OBFUSCATION_QUERY_STRING_REGEXP to the fixed regex below, then restart the application.

```...

Affected versions

PackageAffectedFixed in
dd-trace
npm
>= 5.131.0, < 5.131.15.131.1
>= 6.0.0, < 6.20.16.20.1
Details and references

### Summary A regular expression used to obfuscate URL query strings can consume excessive CPU when processing certain attacker-controlled input. This can stall request processing and cause denial of service in applications using affected HTTP tracing integrations. ### Details The default query-string obfuscation pattern can exhibit excessive backtracking. The pattern is applied synchronously when recording HTTP URL metadata, allowing query-string processing to occupy application resources for an extended period. As a workaround, set DD_TRACE_OBFUSCATION_QUERY_STRING_REGEXP to the fixed regex below, then restart the application. ``` DD_TRACE_OBFUSCATION_QUERY_STRING_REGEXP='(?:(?:"|%22)?)(?:(?:old[-_]?|new[-_]?)?p(?:ass)?w(?:or)?d(?:1|2)?|pass(?:[-_]?phrase)?|secret|(?:api[-_]?|private[-_]?|public[-_]?|access[-_]?|secret[-_]?|app(?:lication)?[-_]?)key(?:[-_]?id)?|token|consumer[-_]?(?:id|key|secret)|sign(?:ed|ature)?|auth(?:entication|orization)?)(?:(?:\s|%20)*(?:=|%3D)[^&]+|(?:"|%22)(?:\s|%20)*(?::|%3A)(?:\s|%20)*(?:"|%22)(?:%2[^2]|%[^2]|[^"%])+(?:"|%22))|(?:bearer(?:\s|%20)+[a-z0-9._\-]+|token(?::|%3A)[a-z0-9]{13}|gh[opsu]_[0-9a-zA-Z]{36}|(?:(?<![\w-])|(?<=%[0-9a-f]{2}))ey[I-L][\w-]+(?:=|%3D)*\.ey[I-L][\w-]+(?:=|%3D)*(?:\.(?:[\w.+/=-]|%3D|%2F|%2B)+)?|-{5}BEGIN(?:[a-z\s]|%20)+PRIVATE(?:\s|%20)KEY-{5}[^\-]+-{5}END(?:[a-z\s]|%20)+PRIVATE(?:\s|%20)KEY(?:-{5})?(?:\n|%0A)?|(?:ssh-(?:rsa|dss)|ecdsa-[a-z0-9]+-[a-z0-9]+)(?:\s|%20|%09)+(?:[a-z0-9/.+]|%2F|%5C|%2B){100,}(?:=|%3D)*(?:(?:\s|%20|%09)+[a-z0-9._-]+)?)' ``` ### Proof of concept Detailed triggering inputs and reproduction steps are omitted from this advisory. The patched version includes regression coverage for the affected behavior. ### Impact Regular expression denial of service (ReDoS) affecting applications that process attacker-controlled URL query strings through the vulnerable obfuscation pattern. Successful exploitation can cause excessive CPU consumption, prolonged request latency, and service unavailability. The vulnerable processing is enabled by default for affected HTTP integrations that include query strings in URL span tags.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)

More Datadog advisories

All Datadog