---
id: CVE-2026-40983
title: >-
  In Micrometer, it is possible for a user to provide specially crafted gRPC
  requests that may cause a denial-of-service (DoS) condition.


  Affected versions:

  Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
summary: >-
  In Micrometer, it is possible for a user to provide specially crafted gRPC
  requests that may cause a denial-of-service (DoS) condition.


  Affected versions:

  Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-770
vendor: Spring
product: Micrometer
affected:
  - Micrometer >= 1.16.0 < 1.16.5.1
  - Micrometer >= 1.15.0 < 1.15.11.1
patched:
  - build_of_keycloak 26.6
  - amq_broker 7.14.1
  - build_of_apache_camel_4_18_for_quarkus 3.33
  - data_grid 8.6.2
  - openshift_dev_spaces 3.30
  - build_of_keycloak 26.6.5
  - streams_for_apache_kafka 3.2.1
published: '2026-06-09'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T13:18:33.370'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40983'
references:
  - url: 'https://spring.io/security/cve-2026-40983'
    label: security@vmware.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:36839'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:41951'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:50848'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:50849'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:54435'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:62260'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:66488'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-40983'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2486697'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40983.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-40983'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40983'
  - url: 'https://github.com/advisories/GHSA-w737-wx49-qj23'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69459'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - ghsa
  - maven
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-06-09T13:53:39.829639Z'
epss: 0.00631
epssPercentile: 0.48898
aliases:
  - GHSA-w737-wx49-qj23
ecosystem: maven
ingestedAt: '2026-07-06T17:44:51.180Z'
---

## Overview

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.

Affected versions:
Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-40983)

Affected packages:

- `io.micrometer:micrometer-core >= 1.16.0, <= 1.16.5`
- `io.micrometer:micrometer-core >= 1.15.0, <= 1.15.11`

Patched in:

- `io.micrometer:micrometer-core 1.16.6`
- `io.micrometer:micrometer-core 1.15.12`

Source: https://github.com/advisories/GHSA-w737-wx49-qj23

## Vendor advisories

- **RHSA-2026:50849** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50849)
- **RHSA-2026:66488** · Red Hat · fixed in: Red Hat AMQ Broker 7.14.1 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66488)
- **RHSA-2026:36839** · Red Hat · fixed in: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36839)
- **RHSA-2026:41951** · Red Hat · fixed in: Red Hat Data Grid 8.6.2 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:41951)
- **RHSA-2026:62260** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62260)
- **RHSA-2026:50848** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.5 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50848)
- **RHSA-2026:54435** · Red Hat · fixed in: Streams for Apache Kafka 3.2.1 · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54435)
- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat Build of Keycloak, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform Expansion Pack · no fix planned: Red Hat build of Apicurio Registry 3, Red Hat Fuse 7, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40983.json)
- **RHSA-2026:69459** · Red Hat · fixed in: AMQ Clients 2026.Q3 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69459)
