Input validation error in Micrometer - CVE-2026-40983
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ObservationGrpcServerInterceptor when handling specially crafted gRPC requests. A remote attacker can send a specially crafted gRPC request to cause a denial of service.
The issue is exposed only when observations are recorded and metrics are output through DefaultMeterObservationHandler or a similarly behaving custom ObservationHandler.
Affected software
Crowd Data Center
Bitbucket Data Center
Confluence Data Center
Jira Software Data Center
Jira Service Management Data Center
Bamboo Data Center
Red Hat build of Quarkus
Red Hat Camel for Spring Boot
JBoss Data Grid
How to mitigate CVE-2026-40983
Crowd Data Center - update to 7.2.2
Bitbucket Data Center - update to 10.2.5
Confluence Data Center - update to 10.2.14
Jira Software Data Center - update to 11.3.8
Jira Service Management Data Center - update to 11.3.8
Bamboo Data Center - update to 12.1.10
Red Hat build of Quarkus - update to 3.33.2.SP2
Red Hat Camel for Spring Boot - update to 4.18
JBoss Data Grid - update to 8.6.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Micrometer
- Multiple vulnerabilities in Red Hat build of Quarkus 3.33.2
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4
- Multiple vulnerabilities in JBoss Data Grid 8.6
- Multiple vulnerabilities in Bamboo Data Center
- Input validation error in Bitbucket Data Center
- Multiple vulnerabilities in Confluence Data Center
- Multiple vulnerabilities in Crowd Data Center
- Multiple vulnerabilities in Jira Service Management Data Center
- Multiple vulnerabilities in Jira Software Data Center