Denial-of-Service Vulnerability in Micrometer by Pivotal Software
CVE-2026-40983

7.5HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-40983?

A denial-of-service vulnerability in Micrometer allows users to send specially crafted gRPC requests. If exploited, this may lead to service disruption, impacting the availability and performance of applications reliant on Micrometer. Versions 1.16.0 through 1.16.5 and 1.15.0 through 1.15.11 are particularly affected, necessitating immediate attention from users to safeguard their systems against potential threats.

Affected Version(s)

Micrometer 1.16.0 < 1.16.5.1

Micrometer 1.15.0 < 1.15.11.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.