CVE-2026-40983
Received
Received - Intake
Denial-of-Service in Micrometer via gRPC Requests
Publication date: 2026-06-09
Last updated on: 2026-06-09
Assigner: VMware
Description
Description
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.
Affected versions:
Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| vmware | micrometer | From 1.15.0 (inc) to 1.16.5 (inc) |
| vmware | micrometer | From 1.15.0 (inc) to 1.15.11 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |