These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-50274 is a denial of service vulnerability in Datadog's dd-trace-go library prior to version 2.8.1, used for application performance monitoring, profiling, and security monitoring. The vulnerability allows a remote, unauthenticated attacker to cause unbounded CPU and memory consumption by sending a request with a large number of comma-separated key-value pairs or a single very large value in the [truncated]
CVE-2026-50272 is a high-severity vulnerability in the Datadog APM client for Node.js, allowing for a remote denial of service via unbounded CPU and memory consumption. The issue was fixed in version 5.100.0. This vulnerability affects users of Datadog APM client for Node.js, especially those with baggage propagation enabled. The vulnerability allows a remote, unauthenticated attacker to send a request wi [truncated]
CVE-2026-50271 is a denial of service vulnerability in Datadog's dd-trace-py, a Python APM client. The issue allows for remote, unauthenticated attackers to cause unbounded CPU and memory consumption via specially crafted baggage HTTP headers. This vulnerability has a high impact on users of Datadog's dd-trace-py, especially those with exposure to untrusted HTTP traffic. Successful exploitation enables a [truncated]
CVE-2026-50273 is a vulnerability in Datadog .NET Tracer that allows remote unauthenticated attackers to cause unbounded CPU and memory consumption. The issue is fixed in version 3.43.0. The vulnerability affects Datadog .NET Tracer prior to version 3.43.0 and has a high CVSS score of 7.5. The vulnerability is related to the parsing of incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_I [truncated]
GuardDog, a CLI tool for identifying malicious PyPI packages, contains an output sanitization flaw in versions 2.6.0 through 2.9.0. The tool includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-readable output without escaping terminal control characters. This allows a malicious package to inject ANSI or OSC escape sequences into analyst terminals or CI [truncated]
GuardDog, a CLI tool for identifying malicious PyPI packages, contains a critical vulnerability in its programmatic remote project scanning functionality from versions 1.0.0 to 2.9.0. The flaw stems from improper handling of attacker-controlled repository URLs through blind string replacement, combined with the transmission of the caller's GitHub credentials alongside the modified request. This enables Se [truncated]