Memory leak in Micrometer - CVE-2026-59295
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unbounded memory leak in MicrometerHttpClientInterceptor when handling outbound asynchronous HTTP requests that fail before any response message is received. A remote attacker can cause pre-response transport failures to cause a denial of service.
Exploitation requires a Micrometer-instrumented Apache HttpAsyncClient and outbound requests to a hostile or unreliable remote endpoint, or requests that can be subjected to pre-response transport failures.