Denial-of-Service Vulnerabilities in Micrometer Identified

Denial-of-Service Vulnerabilities in Micrometer Identified

First seen 8 Jun 2026, 16:19 UTC spring.io 92% similarity 45.6

Article Content

Browse articles
ThreatCluster

Two denial-of-service (DoS) vulnerabilities have been identified in Micrometer, affecting HTTP and gRPC server instrumentations. CVE-2026-40984 allows specially crafted HTTP requests to cause DoS conditions, impacting unsupported versions. CVE-2026-40983 similarly affects gRPC requests but is limited to versions prior to 1.15.0. Users of the affected versions are advised to upgrade to the fixed versions. Both issues were reported by Yu Bao from PayPal. No further mitigation steps are necessary beyond upgrading. The vulnerabilities do not appear to be actively exploited at this time.

Key Points: • CVE-2026-40984 and CVE-2026-40983 are DoS vulnerabilities in Micrometer. • Affected users should upgrade to fixed versions; no additional mitigation is needed. • Both vulnerabilities were reported by Yu Bao from PayPal.

ThreatCluster AI

Timeline

2026-06-08
CVE-2026-40984 disclosed
Micrometer's HTTP server instrumentation vulnerability allows DoS via crafted requests, affecting unsupported versions.
spring.io
2026-06-08
CVE-2026-40983 disclosed
Micrometer's gRPC server instrumentation vulnerability allows DoS via crafted requests, affecting versions prior to 1.15.0.
spring.io

Community

Browse all →