Input validation error in Micrometer - CVE-2026-40984
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in HTTP server instrumentations when handling specially crafted HTTP requests. A remote attacker can send a specially crafted HTTP request to cause a denial of service.
The issue affects applications only when one or more HTTP server instrumentations are configured and metrics are recorded through the instrumentation.
Affected software
Crowd Data Center
Bamboo Data Center
Red Hat build of Quarkus
Red Hat Camel for Spring Boot
JBoss Data Grid
How to mitigate CVE-2026-40984
Crowd Data Center - update to 7.2.2
Bamboo Data Center - update to 12.1.10
Red Hat build of Quarkus - addressed in versions 3.27.4.SP2, 3.33.2.SP2
Red Hat Camel for Spring Boot - update to 4.18
JBoss Data Grid - update to 8.6.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Micrometer
- Multiple vulnerabilities in Red Hat build of Quarkus 3.27.4
- Multiple vulnerabilities in Red Hat build of Quarkus 3.33.2
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4
- Multiple vulnerabilities in JBoss Data Grid 8.6
- Multiple vulnerabilities in Bamboo Data Center
- Multiple vulnerabilities in Crowd Data Center