Micrometer Core & Jetty 1.131.16.5 DoS via crafted HTTP reqs
CVE-2026-40984 Published on June 9, 2026
Micrometer HTTP server instrumentations DoS vulnerability
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Affected versions:
micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17.
micrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.
micrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.
Vulnerability Analysis
CVE-2026-40984 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
What is a Resource Exhaustion Vulnerability?
The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVE-2026-40984 has been classified to as a Resource Exhaustion vulnerability or weakness.
Products Associated with CVE-2026-40984
Want to know whenever a new CVE is published for VMware Spring Framework? stack.watch will email you.
Affected Versions
Spring Micrometer:- Version 1.16.0 and below 1.16.6 is affected.
- Version 1.15.0 and below 1.15.12 is affected.
- Version 1.14.0 and below 1.14.16 is affected.
- Version 1.13.0 and below 1.13.19 is affected.
- Version 1.9.0 and below 1.9.18 is affected.
- Version 1.16.0 and below 1.16.6 is affected.
- Version 1.15.0 and below 1.15.12 is affected.
- Version 1.14.0 and below 1.14.16 is affected.
- Version 1.13.0 and below 1.13.19 is affected.
- Version 1.16.0 and below 1.16.6 is affected.
- Version 1.15.0 and below 1.15.12 is affected.
- Version 1.14.0 and below 1.14.16 is affected.
- Version 1.13.0 and below 1.13.19 is affected.