GHSA-579q-h82j-r5v2 · Severity: critical · Ecosystem: maven — dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code execution
dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability: First, dd-trace-java is attached as a Java agent (`-javaagent`) on Java 16 or earlier. Second, a JMX/RMI port has been explicitly configured via `-Dcom.sun.management.jmxremote.port` and is network-reachable, Third, a gadget-chain-compatible library is present on the classpath. For JDK >= 17, no action is required, but upgrading is strongly encouraged. For JDK >= 8u121 < JDK 17, upgrade to dd-trace-java version 1.60.3 or later. For JDK < 8u121 and earlier where serialization filters are not available, apply the workaround. The workaround is to set the following environment variable to disable the RMI integration: `DD_INTEGRATION_RMI_ENABLED=false`.
Conclusion & alert: CVE-2026-33728 is rated Moderate Risk (54.3/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.26%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-28 | 0.23% | 0.26% | +0.02% |
| 2 | 2026-04-21 | 0.75% | 0.23% | -0.52% |
| 3 | 2026-04-02 | — | 0.75% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 4.0 | CRITICAL |
|
— | — | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-579q-h82j-r5v2 · Severity: critical · Ecosystem: maven — dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code execution
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| datadog | dd-trace-java | >= 0.40.0, < 1.60.3 | cpe:2.3:a:datadog:dd-trace-java:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/DataDog/dd-trace-java/releases/tag/v1.60.3 | Product Release Notes |
| https://github.com/DataDog/dd-trace-java/security/advisories/GHSA-579q-h82j-r5v2 | Mitigation Vendor Advisory |