com.datadoghq:dd-java-agent
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.datadoghq:dd-java-agentpage 1 of 1
- CVE-2026-33728CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.60.32026-03-27
vulnerable: 0.100.0 ... 1.9.0 (214 versions)
dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JD…
- CVE-2026-50270HIGHCVSS 7.5EG 7.5✓ Fixed in 1.62.02026-07-15
vulnerable: 0.0.1 ... 1.9.0 (291 versions)
dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply d…
Check whether com.datadoghq:dd-java-agent is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.datadoghq:dd-java-agent CVEs against the assets you own.
Start Free Scan →