CVE-2026-39197: Medium severity Datadog Vector vulnerability

Published Jun 15, 2026
·
Updated

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or payload.

Affected Software

1 affected component
Datadog Vector=0.54.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Datadog Vector v0.54.0 from your environment.

    If Datadog Vector v0.54.0 is not required, uninstall or replace it until an upstream fix is available.

  2. Configuration

    Disable the /util/http/prelude.rs HTTP endpoint or configure the Vector HTTP server to reject or restrict requests to this route to prevent crafted requests or payloads from reaching it.

    Datadog Vector HTTP endpoint /util/http/prelude.rs access = disabled or restricted
  3. Compensating control

    Deploy WAF or reverse-proxy rules to detect and block malformed or suspicious requests targeting /util/http/prelude.rs and implement HTTP rate-limiting on Vector endpoints to mitigate DoS attempts.

  4. Compensating control

    Restrict network access to the Vector HTTP endpoint to trusted IPs using firewall rules or network ACLs so only necessary sources can reach the service.

Event History

Jun 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-39197?

The severity of CVE-2026-39197 is medium with a CVSS score of 6.5.

2

What type of vulnerability is CVE-2026-39197?

CVE-2026-39197 is a Denial of Service (DoS) vulnerability.

3

How do I fix CVE-2026-39197?

To fix CVE-2026-39197, update to the latest version of Datadog Vector that addresses this vulnerability.

4

What software is affected by CVE-2026-39197?

CVE-2026-39197 affects Datadog Vector version 0.54.0.

5

When was CVE-2026-39197 published?

CVE-2026-39197 was published on June 15, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203