datadog
Enterprise Softwarecommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting datadog.
- CVE-2026-47364In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and cra...6.5
- CVE-2026-47363In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with ...6.3
- CVE-2026-44965In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCa...5.5
- CVE-2026-44964In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-...6.5
- CVE-2026-47362In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, re...4.6
- CVE-2026-47361In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When th...6.4
- CVE-2026-50271dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS7.5
- CVE-2026-50274dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS7.5
- CVE-2026-50272dd-trace: Improper parsing of W3C baggage headers may lead to DoS7.5
- CVE-2026-50273Datadog .NET Tracer: Improper parsing of W3C baggage headers may lead to DoS7.5
- CVE-2026-44971GuardDog: Blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltration8.2
- CVE-2026-44972GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content5.0
- CVE-2026-33728dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code execution9.8
- CVE-2026-22871GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE9.8
- CVE-2026-22870GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS7.5