Metaspace leak in Spring Boot / Tomcat apps after upgrading to 1.64.0 — tied to DD_APPSEC_SCA_ENABLED
@jandro996 is already working on this.
Since Jul 17, 2026.
Assessment
This issue has not been assessed yet.
Description
Tracer Version(s)
1.64.0
Java Version(s)
21.0.11
JVM Vendor
Amazon Corretto
Bug Report
After upgrading dd-trace-java from 1.63.2 to 1.64.0, our Spring Boot applications (Tomcat based) started running out of Metaspace within about a day of deployment. Metaspace grows continuously in a straight line rather than plateauing, until it hits the configured limit and the JVM/pod is killed.
Downgrading to 1.63.2 with no other changes resolves the issue. On 1.64.0, setting DD_APPSEC_SCA_ENABLED=false also resolves it (all other flags unchanged). This strongly points at the SCA reachability work shipped in 1.64.0 (possibly #11352 "Implement SCA Reachability runtime detection" and/or #11614 "Migrate SCA Reachability to method-level symbol database") as the likely root cause, but we haven't been able to confirm the exact mechanism from our side.
I created a Datadog Helpdesk issue for this as well at Request #2955022 (with uploaded class load file).
Expected Behavior
Expected behavior
Metaspace usage should stabilize after the application warms up (JIT/class loading settles), as it did on 1.63.2 and as it does on 1.64.0 when Datadog instrumentation is fully disabled.
Actual behavior
Metaspace (jvm.gc.metaspace_size) grows continuously and roughly linearly for the life of the process. Example from one affected pod:
15:00 — Metaspace: ~110 MB
06:00 next day — Metaspace: ~200 MB
Growth does not plateau; left running, the process eventually hits the configured Metaspace limit and OOMs. This started the same day we rolled out a new image built against 1.64.0 — no other code or config changes shipped alongside it.
Reproduction Code
Run a Spring Boot (Tomcat) service on Java 21 with dd-java-agent 1.64.0 and the configuration above (in particular DD_APPSEC_SCA_ENABLED=true).
Let it run under normal traffic for several hours while monitoring jvm.gc.metaspace_size (or jcmd VM.metaspace / a JFR/heap capture).
Observe continuous, non-plateauing Metaspace growth until the container is OOM-killed (roughly within 24h in our environment, depending on Metaspace limit and traffic).
- Dominant language
- Java
- Stars
- 737
- Forks
- 361
- Avg merge
- 3d 20h
- Merged PRs (30d)
- 173
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from DataDog/dd-trace-java
-
type: feature request
Difficulty 1/5 1-3 hours Newbie friendliness 70/100
DataDog/dd-trace-java#10245 · 1 comment ·
-
Difficulty 4/5 3-5 days Newbie friendliness 62/100
DataDog/dd-trace-java#12608 ·
-
type: bug report
Difficulty 4/5 3-5 days Newbie friendliness 35/100
DataDog/dd-trace-java#12597 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
DataDog/dd-trace-java#12540 · 3 comments · 1 assignee ·
-
Difficulty 3/5 1-2 days Newbie friendliness 25/100
DataDog/dd-trace-java#12480 ·
All issues in DataDog/dd-trace-java
Similar issues
-
certification
Difficulty 1/5 Under an hour Newbie friendliness 80/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
[BUG] ECR GetAuthorizationToken returns a proxyEndpoint for the default region, not the request's Openbug ecr
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Needs: Triage Type: Feature request
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
AntennaPod/AntennaPod#8794 ·
-
agentic-workflows
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
github/copilot-sdk#2760 ·