CVE-2026-40983
Received Received - Intake
Denial-of-Service in Micrometer via gRPC Requests

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: VMware

Description
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-09
AI Q&A
2026-06-09
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
vmware micrometer From 1.15.0 (inc) to 1.16.5 (inc)
vmware micrometer From 1.15.0 (inc) to 1.15.11 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-40983 is a denial-of-service (DoS) vulnerability in Micrometer's gRPC server instrumentation. It occurs when a user sends specially crafted gRPC requests to an application using a vulnerable version of Micrometer (versions 1.15.0 to 1.15.11 and 1.16.0 to 1.16.5). The vulnerability affects applications that use an ObservationRegistry, have a DefaultMeterObservationHandler or a similar custom ObservationHandler for metrics output, and employ ObservationGrpcServerInterceptor for gRPC server instrumentation.

This specially crafted request can cause the application to enter a denial-of-service state, making it unavailable to legitimate users.

Impact Analysis

This vulnerability can cause a denial-of-service (DoS) condition in applications using vulnerable versions of Micrometer with gRPC server instrumentation. An attacker can send crafted gRPC requests that disrupt the normal operation of the application, potentially making it unavailable to legitimate users.

The impact is primarily availability-related, as indicated by the CVSS score which rates the impact on availability as high, while confidentiality and integrity are not affected.

Mitigation Strategies

To mitigate the CVE-2026-40983 vulnerability, you should upgrade Micrometer to the fixed versions.

  • Upgrade to version 1.15.12 if you are using the 1.15.x branch.
  • Upgrade to version 1.16.6 if you are using the 1.16.x branch.

No additional mitigation steps are required beyond upgrading to these fixed versions.

Compliance Impact

The provided information does not specify any direct impact of this denial-of-service (DoS) vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40983. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart