Vulnerability DatabaseGHSA-qvgg-r6rq-vwfx

GHSA-qvgg-r6rq-vwfx
PHP vulnerability analysis and mitigation

Overview

The vulnerability affects datadog/dd-trace PHP library versions 0.30.0 to 0.30.2, where the ddtrace.request_init_hook circumvents the open_basedir INI directive. This security issue was discovered and disclosed in September 2019, impacting the core functionality of the PHP tracer extension (GitHub Advisory).

Technical details

The vulnerability stems from the request init hook not being properly bound by the open_basedir INI directive, which is a PHP security feature that limits file operations to specific directories. The issue was identified in the core extension functionality where PG(open_basedir) was being set to NULL, effectively bypassing the security restrictions (DataDog Commit).

Impact

The vulnerability allows the request init hook to bypass open_basedir restrictions, potentially enabling access to files and directories that should be restricted by PHP's security settings. This could lead to unauthorized file access outside of the intended directory scope (Security Advisory).

Exploitability

The vulnerability affects versions 0.30.0 and 0.30.1 of the datadog/dd-trace package. While no specific exploit reports were found in the wild, the vulnerability could be exploited in environments relying on open_basedir for security restrictions (GitHub Release).

Mitigation and workarounds

The issue was fixed in version 0.30.2 of datadog/dd-trace. Users are strongly recommended to upgrade to this version or later. The fix ensures that the request init hook remains properly bound by the open_basedir INI directive and includes additional sandboxing mechanisms to prevent errors or exceptions from affecting the main script execution (GitHub Release).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-85400HIGH7.5
  • PHP logoPHP
  • composer://typo3/cms-lowlevel
NoYesSep 08, 2026
CVE-2026-53637MEDIUM6.5
  • PHP logoPHP
  • sylius/sylius
NoYesSep 08, 2026
CVE-2026-53639MEDIUM6.3
  • PHP logoPHP
  • sylius/sylius
NoYesSep 08, 2026
CVE-2026-77132MEDIUM5.3
  • PHP logoPHP
  • cpe:2.3:a:typo3:typo3
NoYesSep 08, 2026
CVE-2026-53638MEDIUM4.3
  • PHP logoPHP
  • sylius/sylius
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management