spring.io
Denial-of-Service Vulnerabilities in Micrometer Identified
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two denial-of-service (DoS) vulnerabilities have been identified in Micrometer, affecting HTTP and gRPC server instrumentations. CVE-2026-40984 allows specially crafted HTTP requests to cause DoS conditions, impacting unsupported versions. CVE-2026-40983 similarly affects gRPC requests but is limited to versions prior to 1.15.0. Users of the affected versions are advised to upgrade to the fixed versions. Both issues were reported by Yu Bao from PayPal. No further mitigation steps are necessary beyond upgrading. The vulnerabilities do not appear to be actively exploited at this time.
Key Points: • CVE-2026-40984 and CVE-2026-40983 are DoS vulnerabilities in Micrometer. • Affected users should upgrade to fixed versions; no additional mitigation is needed. • Both vulnerabilities were reported by Yu Bao from PayPal.