Vulnerabilities in DataDog

15 results
Vexday analysis

Datadog possui 15 CVEs registradas, com 1 crítica e nenhuma sob ataque ativo no momento, reduzindo a exposição imediata. A fraqueza dominante é CWE-770 (alocação de recursos sem limite), que afeta principalmente a disponibilidade dos serviços. O risco recente é moderado: 6 vulnerabilidades publicadas nos últimos 90 dias indicam que correções contínuas são necessárias, mas o padrão de ataque ainda não atingiu a base de clientes de forma massiva.

CVE-2023-38704HIGHimport-in-the-middle allows unsanitized user controlled input in module generationEPSS 1.0%CVE-2026-22871HIGHGuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCEEPSS 0.9%CVE-2022-23530MEDIUMGuardDog vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI packageEPSS 0.7%CVE-2026-33728CRITICALdd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code executionEPSS 0.6%CVE-2022-23531MEDIUMArbitrary file write when scanning a specially-crafted local PyPI packageEPSS 0.6%CVE-2021-21331LOWDataDog API Client contains a Local Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-50273HIGHDatadog .NET Tracer: Improper parsing of W3C baggage headers may lead to DoSEPSS 0.5%CVE-2026-50271HIGHdd-trace-py: Improper parsing of W3C baggage headers may lead to DoSEPSS 0.4%CVE-2026-50274HIGHdd-trace-go: Improper parsing of W3C baggage headers may lead to DoSEPSS 0.4%CVE-2026-50272HIGHdd-trace: Improper parsing of W3C baggage headers may lead to DoSEPSS 0.4%CVE-2024-38525HIGHdd-trace-cpp malformed unicode header values may cause crashEPSS 0.4%CVE-2026-22870HIGHGuardDog Zip Bomb Vulnerability in safe_extract() Allows DoSEPSS 0.4%CVE-2026-44971HIGHGuardDog: Blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltrationEPSS 0.2%CVE-2026-44972MEDIUMGuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package contentEPSS 0.1%CVE-2025-61667HIGHDatadog Linux Host Agent affected by local privilege escalation due to insufficient pycache permissionsEPSS 0.1%