CVE-2026-40984: Micrometer HTTP server instrumentations DoS vulnerability
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17. micrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18. micrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40984?
CVE-2026-40984 has a high severity rating of 7.5.
How do I fix CVE-2026-40984?
To fix CVE-2026-40984, upgrade to the latest version of micrometer-core or its related dependencies.
What is the main risk associated with CVE-2026-40984?
The main risk of CVE-2026-40984 is a denial-of-service (DoS) condition caused by specially crafted HTTP requests.
Which versions are affected by CVE-2026-40984?
CVE-2026-40984 affects micrometer-core versions 1.16.0 through 1.16.5, 1.15.0 through 1.15.11, 1.14.0 through 1.14.15, 1.13.0 through 1.13.18, and 1.9.0 through 1.9.17.
What components are impacted by CVE-2026-40984?
The components impacted by CVE-2026-40984 include micrometer-core and related artifacts such as micrometer-jetty11 and micrometer-jetty12.