Input validation error in Micrometer - CVE-2026-40984

 

Input validation error in Micrometer - CVE-2026-40984

Published: August 31, 2026


Vulnerability identifier: #VU146376
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40984
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in HTTP server instrumentations when handling specially crafted HTTP requests. A remote attacker can send a specially crafted HTTP request to cause a denial of service.

The issue affects applications only when one or more HTTP server instrumentations are configured and metrics are recorded through the instrumentation.


Affected software

Micrometer
Crowd Data Center
Bamboo Data Center
Red Hat build of Quarkus
Red Hat Camel for Spring Boot
JBoss Data Grid

How to mitigate CVE-2026-40984

Install security update from vendor's website.

Micrometer - addressed in versions 1.9.18, 1.13.19, 1.14.16, 1.15.12, 1.16.6
Crowd Data Center - update to 7.2.2
Bamboo Data Center - update to 12.1.10
Red Hat build of Quarkus - addressed in versions 3.27.4.SP2, 3.33.2.SP2
Red Hat Camel for Spring Boot - update to 4.18
JBoss Data Grid - update to 8.6.2

External References

Related Security Bulletins