{"id":"CVE-2026-40983","title":"In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.\n\nAffected versions:\nMicrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.","summary":"In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.\n\nAffected versions:\nMicrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-770"],"vendor":"Spring","product":"Micrometer","affected":["Micrometer >= 1.16.0 < 1.16.5.1","Micrometer >= 1.15.0 < 1.15.11.1"],"patched":["build_of_keycloak 26.6","amq_broker 7.14.1","build_of_apache_camel_4_18_for_quarkus 3.33","data_grid 8.6.2","openshift_dev_spaces 3.30","build_of_keycloak 26.6.5","streams_for_apache_kafka 3.2.1"],"published":"2026-06-09","updated":"2026-09-14","sourceUpdated":"2026-09-14T13:18:33.370","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-40983","references":[{"url":"https://spring.io/security/cve-2026-40983","label":"security@vmware.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:36839","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:41951","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:50848","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:50849","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:54435","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:62260","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:66488","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-40983","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2486697","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40983.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-40983"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40983"},{"url":"https://github.com/advisories/GHSA-w737-wx49-qj23"},{"url":"https://access.redhat.com/errata/RHSA-2026:69459"}],"tags":["nvd","cve.org","csaf","vex","red-hat","ghsa","maven"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-06-09T13:53:39.829639Z"},"epss":0.00631,"epssPercentile":0.48866,"aliases":["GHSA-w737-wx49-qj23"],"ecosystem":"maven","ingestedAt":"2026-07-06T17:44:51.180Z","slug":"CVE-2026-40983","body":"## Overview\n\nIn Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.\n\nAffected versions:\nMicrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-40983)\n\nAffected packages:\n\n- `io.micrometer:micrometer-core >= 1.16.0, <= 1.16.5`\n- `io.micrometer:micrometer-core >= 1.15.0, <= 1.15.11`\n\nPatched in:\n\n- `io.micrometer:micrometer-core 1.16.6`\n- `io.micrometer:micrometer-core 1.15.12`\n\nSource: https://github.com/advisories/GHSA-w737-wx49-qj23\n\n## Vendor advisories\n\n- **RHSA-2026:50849** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50849)\n- **RHSA-2026:66488** · Red Hat · fixed in: Red Hat AMQ Broker 7.14.1 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66488)\n- **RHSA-2026:36839** · Red Hat · fixed in: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36839)\n- **RHSA-2026:41951** · Red Hat · fixed in: Red Hat Data Grid 8.6.2 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:41951)\n- **RHSA-2026:62260** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62260)\n- **RHSA-2026:50848** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.5 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50848)\n- **RHSA-2026:54435** · Red Hat · fixed in: Streams for Apache Kafka 3.2.1 · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54435)\n- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat Build of Keycloak, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform Expansion Pack · no fix planned: Red Hat build of Apicurio Registry 3, Red Hat Fuse 7, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40983.json)\n- **RHSA-2026:69459** · Red Hat · fixed in: AMQ Clients 2026.Q3 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69459)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}