CVE-2026-59323
Awaiting Analysis Awaiting Analysis - Queue

Denial of Service in Micrometer Tracing Brave Bridge

Vulnerability report for CVE-2026-59323, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-27

Assigner: VMware

Description

An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers. Micrometer Tracing 1.7.0 Micrometer Tracing 1.6.0 - 1.6.6 Micrometer Tracing 1.5.0 - 1.5.12 Micrometer Tracing 1.4.13 and earlier

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-27
Generated
2026-09-10
AI Q&A
2026-08-21
EPSS Evaluated
2026-09-09
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
micrometer micrometer_tracing_bridge_brave 1.4.13
micrometer micrometer_tracing_bridge_brave From 1.5.0 (inc) to 1.5.12 (inc)
micrometer micrometer_tracing_bridge_brave From 1.6.0 (inc) to 1.6.6 (inc)
micrometer micrometer_tracing_bridge_brave 1.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-59323 is a denial-of-service (DoS) vulnerability in applications using Micrometer Tracing with W3C baggage propagation in the Brave bridge. It occurs when processing incoming baggage headers with unbounded object allocation, leading to excessive garbage collection, high CPU usage, and potential application crashes via OutOfMemoryError.

Detection Guidance

To detect this vulnerability, monitor for high CPU usage, excessive garbage collection, or OutOfMemoryError crashes in applications using Micrometer Tracing with W3C baggage propagation. Check application logs for requests with unusually large baggage headers. Use network monitoring tools to inspect incoming HTTP headers for inflated baggage fields.

Impact Analysis

An attacker can send requests with artificially large baggage headers containing many key-value pairs. This causes unconditional allocations of BaggageField objects, leading to garbage collection pressure, high CPU usage, and potential application crashes via OutOfMemoryError.

Compliance Impact

This vulnerability primarily causes denial-of-service (DoS) conditions through excessive resource consumption, which could indirectly impact compliance with standards like GDPR or HIPAA by degrading system availability or performance. However, the CVE itself does not directly violate these regulations unless service disruptions lead to unauthorized data access or processing delays affecting data subject rights.

Mitigation Strategies
  • Upgrade to fixed versions of Micrometer Tracing (1.7.1, 1.6.7, 1.5.13, or 1.4.14) if using vulnerable versions.
  • Restrict or strip incoming baggage headers at network boundaries like API gateways or load balancers as a temporary workaround.
  • Ensure network components limit header size to prevent unbounded object allocation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59323. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart