Input validation error in Micrometer - CVE-2026-40983

 

Input validation error in Micrometer - CVE-2026-40983

Published: August 31, 2026


Vulnerability identifier: #VU146375
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40983
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in ObservationGrpcServerInterceptor when handling specially crafted gRPC requests. A remote attacker can send a specially crafted gRPC request to cause a denial of service.

The issue is exposed only when observations are recorded and metrics are output through DefaultMeterObservationHandler or a similarly behaving custom ObservationHandler.


Affected software

Micrometer
Crowd Data Center
Bitbucket Data Center
Confluence Data Center
Jira Software Data Center
Jira Service Management Data Center
Bamboo Data Center
Red Hat build of Quarkus
Red Hat Camel for Spring Boot
JBoss Data Grid

How to mitigate CVE-2026-40983

Install security update from vendor's website.

Micrometer - addressed in versions 1.15.12, 1.16.6
Crowd Data Center - update to 7.2.2
Bitbucket Data Center - update to 10.2.5
Confluence Data Center - update to 10.2.14
Jira Software Data Center - update to 11.3.8
Jira Service Management Data Center - update to 11.3.8
Bamboo Data Center - update to 12.1.10
Red Hat build of Quarkus - update to 3.33.2.SP2
Red Hat Camel for Spring Boot - update to 4.18
JBoss Data Grid - update to 8.6.2

External References

Related Security Bulletins