Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Metaspace leak in Spring Boot / Tomcat apps after upgrading to 1.64.0 — tied to DD_APPSEC_SCA_ENABLED

オープン
#11,977 コメント 5 件 リアクション 5 件 担当者 1 名 GitHub で見る

@jandro996 がすでに取り組んでいます。

2026年7月17日 から。

評価

この issue はまだ評価されていません。

説明

type: bug report
Tracer Version(s)

1.64.0

Java Version(s)

21.0.11

JVM Vendor

Amazon Corretto

Bug Report

After upgrading dd-trace-java from 1.63.2 to 1.64.0, our Spring Boot applications (Tomcat based) started running out of Metaspace within about a day of deployment. Metaspace grows continuously in a straight line rather than plateauing, until it hits the configured limit and the JVM/pod is killed.

Downgrading to 1.63.2 with no other changes resolves the issue. On 1.64.0, setting DD_APPSEC_SCA_ENABLED=false also resolves it (all other flags unchanged). This strongly points at the SCA reachability work shipped in 1.64.0 (possibly #11352 "Implement SCA Reachability runtime detection" and/or #11614 "Migrate SCA Reachability to method-level symbol database") as the likely root cause, but we haven't been able to confirm the exact mechanism from our side.

I created a Datadog Helpdesk issue for this as well at Request #2955022 (with uploaded class load file).

Expected Behavior

Expected behavior

Metaspace usage should stabilize after the application warms up (JIT/class loading settles), as it did on 1.63.2 and as it does on 1.64.0 when Datadog instrumentation is fully disabled.

Actual behavior

Metaspace (jvm.gc.metaspace_size) grows continuously and roughly linearly for the life of the process. Example from one affected pod:

15:00 — Metaspace: ~110 MB
06:00 next day — Metaspace: ~200 MB

Growth does not plateau; left running, the process eventually hits the configured Metaspace limit and OOMs. This started the same day we rolled out a new image built against 1.64.0 — no other code or config changes shipped alongside it.

Reproduction Code

Run a Spring Boot (Tomcat) service on Java 21 with dd-java-agent 1.64.0 and the configuration above (in particular DD_APPSEC_SCA_ENABLED=true).
Let it run under normal traffic for several hours while monitoring jvm.gc.metaspace_size (or jcmd VM.metaspace / a JFR/heap capture).
Observe continuous, non-plateauing Metaspace growth until the container is OOM-killed (roughly within 24h in our environment, depending on Metaspace limit and traffic).

主要言語
Java
スター
737
フォーク
361
平均マージ
3日 20時間
マージ済み PR(30日)
173

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

DataDog/dd-trace-java のほかの issue

DataDog/dd-trace-java の issue をすべて見る

似ている issue

Java の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。