REDHAT-BUG-2486697: High severity Micrometer Micrometer vulnerability
Published Jun 9, 2026
·Updated
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.
Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
Affected Software
2 affected components
Micrometer Micrometer>=1.16.0<=1.16.5
Micrometer Micrometer>=1.15.0<=1.15.11
Event History
Jun 9, 2026
Data Sourced
via Red Hat·05:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2486697?
The severity of REDHAT-BUG-2486697 is classified as high with a score of 7.
2
How do I fix REDHAT-BUG-2486697?
To fix REDHAT-BUG-2486697, upgrade Micrometer to a version that is not vulnerable, specifically beyond 1.16.5 and 1.15.11.
3
What versions are affected by REDHAT-BUG-2486697?
The affected versions for REDHAT-BUG-2486697 are Micrometer 1.16.0 through 1.16.5 and 1.15.0 through 1.15.11.
4
What type of vulnerability is REDHAT-BUG-2486697?
REDHAT-BUG-2486697 is a denial-of-service (DoS) vulnerability caused by specially crafted gRPC requests.
5
What are the potential impacts of REDHAT-BUG-2486697?
The potential impacts of REDHAT-BUG-2486697 include service disruptions due to denial-of-service conditions.