---
id: CVE-2026-40984
title: >-
  In Micrometer, it is possible for a user to provide specially crafted HTTP
  requests that may cause a denial-of-service (DoS) condition.


  Affected versions:

  micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through
  1.1…
summary: >-
  In Micrometer, it is possible for a user to provide specially crafted HTTP
  requests that may cause a denial-of-service (DoS) condition.


  Affected versions:

  micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through
  1.1…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-770
vendor: Spring
product: micrometer-core
affected:
  - micrometer-core >= 1.16.0 < 1.16.5.1
  - micrometer-core >= 1.15.0 < 1.15.11.1
  - micrometer-core >= 1.14.0 < 1.14.16
  - micrometer-core >= 1.13.0 < 1.13.19
  - micrometer-core >= 1.9.0 < 1.9.18
  - micrometer-jetty11 >= 1.16.0 < 1.16.5.1
  - micrometer-jetty11 >= 1.15.0 < 1.15.11.1
  - micrometer-jetty11 >= 1.14.0 < 1.14.16
  - micrometer-jetty11 >= 1.13.0 < 1.13.19
  - micrometer-jetty12 >= 1.16.0 < 1.16.6
  - micrometer-jetty12 >= 1.15.0 < 1.15.11.
  - micrometer-jetty12 >= 1.14.0 < 1.14.15.1
  - micrometer-jetty12 >= 1.13.0 < 1.13.19
patched:
  - build_of_keycloak 26.6
  - amq_broker 7.13.6
  - amq_broker 7.14.1
  - build_of_apache_camel_4_18_for_quarkus 3.33
  - data_grid 8.6.2
  - openshift_dev_spaces 3.30
  - build_of_apache_camel_4_18_1_p1_for_spring_boot 3.5.16
  - build_of_keycloak 26.6.5
  - streams_for_apache_kafka 3.2.1
published: '2026-06-09'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T13:18:33.703'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40984'
references:
  - url: 'https://spring.io/security/cve-2026-40984'
    label: security@vmware.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:36839'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37390'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:41951'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:50848'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:50849'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:54435'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:62260'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:66488'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:66545'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-40984'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2486716'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40984.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-40984'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40984'
  - url: >-
      https://github.com/micrometer-metrics/micrometer/commit/36da131525228188a36779a28471a76c79213dd4
  - url: 'https://github.com/advisories/GHSA-g3pr-3p32-fp23'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69459'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - ghsa
  - maven
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-06-09T13:49:55.899071Z'
epss: 0.00792
epssPercentile: 0.54853
aliases:
  - GHSA-g3pr-3p32-fp23
ecosystem: maven
ingestedAt: '2026-07-13T13:27:18.020Z'
---

## Overview

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.

Affected versions:
micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17.
micrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.
micrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-40984)

Affected packages:

- `io.micrometer:micrometer-core >= 1.16.0, <= 1.16.5`
- `io.micrometer:micrometer-core >= 1.15.0, <= 1.15.11`
- `io.micrometer:micrometer-core >= 1.14.0, <= 1.14.14`
- `io.micrometer:micrometer-core >= 1.10.0, <= 1.13.15`
- `io.micrometer:micrometer-core <= 1.9.17`
- `io.micrometer:micrometer-jetty12 >= 1.16.0, <= 1.16.5`
- `io.micrometer:micrometer-jetty12 >= 1.15.0, <= 1.15.11`
- `io.micrometer:micrometer-jetty12 >= 1.14.0, <= 1.14.14`
- `io.micrometer:micrometer-jetty12 <= 1.13.15`
- `io.micrometer:micrometer-jetty11 >= 1.16.0, <= 1.16.5`
- `io.micrometer:micrometer-jetty11 >= 1.15.0, <= 1.15.11`
- `io.micrometer:micrometer-jetty11 >= 1.14.0, <= 1.14.14`
- `io.micrometer:micrometer-jetty11 <= 1.13.15`

Patched in:

- `io.micrometer:micrometer-core 1.16.6`
- `io.micrometer:micrometer-core 1.15.12`
- `io.micrometer:micrometer-jetty12 1.16.6`
- `io.micrometer:micrometer-jetty12 1.15.12`
- `io.micrometer:micrometer-jetty11 1.16.6`
- `io.micrometer:micrometer-jetty11 1.15.12`

Source: https://github.com/advisories/GHSA-g3pr-3p32-fp23

## Vendor advisories

- **RHSA-2026:50849** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50849)
- **RHSA-2026:66545** · Red Hat · fixed in: Red Hat AMQ Broker 7.13.6 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66545)
- **RHSA-2026:66488** · Red Hat · fixed in: Red Hat AMQ Broker 7.14.1 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66488)
- **RHSA-2026:36839** · Red Hat · fixed in: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36839)
- **RHSA-2026:41951** · Red Hat · fixed in: Red Hat Data Grid 8.6.2 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:41951)
- **RHSA-2026:62260** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62260)
- **RHSA-2026:37390** · Red Hat · fixed in: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37390)
- **RHSA-2026:50848** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.5 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50848)
- **RHSA-2026:54435** · Red Hat · fixed in: Streams for Apache Kafka 3.2.1 · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54435)
- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat build of OptaPlanner 8, Red Hat Fuse 7, … · no fix planned: Red Hat Fuse 7, Red Hat OpenShift Dev Spaces, Red Hat build of Debezium 3, Red Hat build of OptaPlanner 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40984.json)
- **RHSA-2026:69459** · Red Hat · fixed in: AMQ Clients 2026.Q3 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69459)
