CVE-2026-40984
Received
Received - Intake
Denial-of-Service in Micrometer
Publication date: 2026-06-09
Last updated on: 2026-06-09
Assigner: VMware
Description
Description
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Affected versions:
micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17.
micrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.
micrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| micrometer | micrometer-core | From 1.9.0 (inc) to 1.9.17 (inc) |
| micrometer | micrometer-core | From 1.13.0 (inc) to 1.13.18 (inc) |
| micrometer | micrometer-core | From 1.14.0 (inc) to 1.14.15 (inc) |
| micrometer | micrometer-core | From 1.15.0 (inc) to 1.15.11 (inc) |
| micrometer | micrometer-core | From 1.16.0 (inc) to 1.16.5 (inc) |
| micrometer | micrometer-jetty11 | From 1.16.0 (inc) to 1.16.5 (inc) |
| micrometer | micrometer-jetty11 | From 1.15.0 (inc) to 1.15.11 (inc) |
| micrometer | micrometer-jetty11 | From 1.14.0 (inc) to 1.14.15 (inc) |
| micrometer | micrometer-jetty11 | From 1.13.0 (inc) to 1.13.18 (inc) |
| micrometer | micrometer-jetty12 | From 1.16.0 (inc) to 1.16.5 (inc) |
| micrometer | micrometer-jetty12 | From 1.15.0 (inc) to 1.15.11 (inc) |
| micrometer | micrometer-jetty12 | From 1.14.0 (inc) to 1.14.15 (inc) |
| micrometer | micrometer-jetty12 | From 1.13.0 (inc) to 1.13.18 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |