CVE-2026-40984High· 7.5▾ TwilightIn Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.1…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.6%
Last analysed / modified upstream
0.6% → 0.8%
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17. micrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18. micrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
io.micrometer:micrometer-core >= 1.16.0, <= 1.16.5io.micrometer:micrometer-core >= 1.15.0, <= 1.15.11io.micrometer:micrometer-core >= 1.14.0, <= 1.14.14io.micrometer:micrometer-core >= 1.10.0, <= 1.13.15io.micrometer:micrometer-core <= 1.9.17io.micrometer:micrometer-jetty12 >= 1.16.0, <= 1.16.5io.micrometer:micrometer-jetty12 >= 1.15.0, <= 1.15.11io.micrometer:micrometer-jetty12 >= 1.14.0, <= 1.14.14io.micrometer:micrometer-jetty12 <= 1.13.15io.micrometer:micrometer-jetty11 >= 1.16.0, <= 1.16.5io.micrometer:micrometer-jetty11 >= 1.15.0, <= 1.15.11io.micrometer:micrometer-jetty11 >= 1.14.0, <= 1.14.14io.micrometer:micrometer-jetty11 <= 1.13.15Patched in:
io.micrometer:micrometer-core 1.16.6io.micrometer:micrometer-core 1.15.12io.micrometer:micrometer-jetty12 1.16.6io.micrometer:micrometer-jetty12 1.15.12io.micrometer:micrometer-jetty11 1.16.6io.micrometer:micrometer-jetty11 1.15.12Source: https://github.com/advisories/GHSA-g3pr-3p32-fp23
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40983High· 7.5In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
CVE-2026-44248Medium· 5.3Netty is an asynchronous, event-driven network application framework
CVE-2026-42587High· 7.5Netty is an asynchronous, event-driven network application framework
CVE-2026-12151High· 7.5undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
CVE-2026-44250High· 7.5Netty is a network application framework for development of protocol servers and clients
CVE-2026-44890High· 7.5Netty is a network application framework for development of protocol servers and clients