StackRadar

CVE-2026-50271

High

Advisory

Published 15 Jul 2026In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
ddtracepypi0.32.2, 0.46.0, 0.53.2, 2.19.0+2 more4.8.27
OSV records
GHSA-mw54-j2v2-42hr
Also known as
PYSEC-2026-3461

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2026-50271.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
ddtrace@0.32.2
4.8.2

Open the chart page →

4,568
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-50271.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
ddtrace@2.19.0
4.8.2

Open the chart page →

4,292
airbyteairbyte-v2Verified publisher2.2.01 of 10See more

airbyte airbyte-v2 2.2.0

1 of the 10 container images this version deploys carry CVE-2026-50271.

Container imageDigestPackageFixed in
airbyte/manifest-server:7.23.73b3a670af168
ddtrace@3.16.0
4.8.2

Open the chart page →

12,473
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-50271.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
ddtrace@0.46.0
4.8.2

Open the chart page →

24,917
datadog-apmfairwinds-incubator2.0.01 of 1See more

datadog-apm fairwinds-incubator 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-50271.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
ddtrace@3.16.4
4.8.2

Open the chart page →

2,785
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-50271.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
ddtrace@0.53.2
4.8.2

Open the chart page →

3,999
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-50271.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
ddtrace@2.19.0
4.8.2

Open the chart page →

5,201

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
airbyte/manifest-server:7.23.73b3a670af168
ddtrace@3.16.0
4.8.2
1
codecov/self-hosted-api:24.4.10475cb1c3136
ddtrace@0.46.0
4.8.2
1
datadog/agent:7.22.08f20e56b5311
ddtrace@0.32.2
4.8.2
1
datadog/agent:6aad9994de6a7
ddtrace@0.53.2
4.8.2
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
ddtrace@2.19.0
4.8.2
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
ddtrace@2.19.0
4.8.2
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
ddtrace@3.16.4
4.8.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.