Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Datadog/
  3. Datadog Software Composition Analysis

Datadog Software Composition Analysis

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 28 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

SCA tool for identifying vulnerabilities in open-source dependencies

by Datadog · datadoghq.com · source ↗

Known CVEs (28)10 newAbout this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-47364 ↗MEDIUM 6.5new2026

    In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash …

  • CVE-2026-47363 ↗MEDIUM 6.3new2026

    In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no …

  • CVE-2026-47362 ↗MEDIUM 4.6new2026

    In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recip…

  • CVE-2026-47361 ↗MEDIUM 6.4new2026

    In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the a…

  • CVE-2026-44965 ↗MEDIUM 5.5new2026

    In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallP…

  • CVE-2026-44964 ↗MEDIUM 6.5new2026

    In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-con…

  • CVE-2026-50274 ↗HIGH 7.5new2026

    Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C baggage prop…

  • CVE-2026-50272 ↗HIGH 7.5new2026

    dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incom…

  • CVE-2026-50271 ↗HIGH 7.5new2026

    Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BA…

  • CVE-2026-50273 ↗HIGH 7.5new2026

    Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers wit…

  • CVE-2026-57522 ↗LOW 3.52026

    Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates with…

  • CVE-2026-39197 ↗MEDIUM 6.52026

    An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or payload.

  • CVE-2026-39196 ↗CRITICAL 9.82026

    Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to acc…

  • CVE-2026-9270 ↗CRITICAL 9.12026

    DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_st…

  • CVE-2026-11362 ↗CRITICAL 9.82026

    DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sourc…

  • CVE-2026-33728 ↗CRITICAL 9.82026

    dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data withou…

  • CVE-2025-12697 ↗LOW 2.22026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-…

  • CVE-2025-61667 ↗2025

    The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog Linux Host Agent versions 7.65.0 through 7.70.2 exists due to insufficient permis…

  • CVE-2025-59405 ↗HIGH 7.52025

    The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) contains a clear…

  • CVE-2024-38525 ↗HIGH 7.52024

    dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohm…

  • …and 8 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Application Security (ASPM) products

see all →
  • AI SAST · Arnica
  • Acunetix Web Application & API Security · Acunetix
  • Adronite · Adronite
  • Almanax · Almanax
  • Amplify Security Fix Your Code · Amplify Security
  • Anchore Anchore Enterprise · Anchore
  • Apiiro AI SAST · Apiiro
  • Apiiro ASPM Platform · Apiiro