Micrometer 1.17.0
Micrometer 1.16.0 - 1.16.6
Micrometer 1.15.0 - 1.15.12
Micrometer 1.14.0 - 1.14.16
Micrometer 1.9.18 and earlier
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when asynchronous requests fail before receiving a response (e.g. connection resets or timeouts). Tracking state for these requests remains in memory indefinitely, and sustained failures lead to heap exhaustion and OutOfMemoryError crashes. | It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) condition due to an unbounded memory leak. Micrometer 1.17.0 Micrometer 1.16.0 - 1.16.6 Micrometer 1.15.0 - 1.15.12 Micrometer 1.14.0 - 1.14.16 Micrometer 1.9.18 and earlier |
| Title | Micrometer Instrumentation of Apache HttpAsyncClient Denial of Service Vulnerability | Micrometer instrumentation of Apache HttpAsyncClient DoS vulnerability |
| Weaknesses | CWE-401 | CWE-772 |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 24 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring micrometer |
|
| Vendors & Products |
Spring
Spring micrometer |
Mon, 24 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when asynchronous requests fail before receiving a response (e.g. connection resets or timeouts). Tracking state for these requests remains in memory indefinitely, and sustained failures lead to heap exhaustion and OutOfMemoryError crashes. | |
| Title | Micrometer Instrumentation of Apache HttpAsyncClient Denial of Service Vulnerability | |
| Weaknesses | CWE-401 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-08-27T17:57:52.554Z
Reserved: 2026-07-04T18:13:34.323Z
Link: CVE-2026-59295
Updated: 2026-08-24T14:28:39.220Z
Status : Awaiting Analysis
Published: 2026-08-24T11:16:39.780
Modified: 2026-08-28T18:47:30.163
Link: CVE-2026-59295
OpenCVE Enrichment
Updated: 2026-08-28T20:15:06Z