Injection Vulnerability in Micrometer Registry StatsD and Core Products
CVE-2026-59296
What is CVE-2026-59296?
This vulnerability arises when untrusted, non-normalized input, such as metric names and tag values, is used within the Micrometer Registry StatsD and Core products. When applications utilize these components without proper sanitization of newline characters, they open themselves up to injection attacks. Specifically, for the StatsD registry employing Datadog or Etsy flavors, the newline-delimited protocol makes them susceptible to line-protocol injection attacks. Furthermore, the LoggingMeterRegistry can experience metric and log spoofing due to how output is treated in logs. Attackers can exploit this by injecting line terminators, enabling them to spoof arbitrary metrics or disrupt log integrity, leading to serious security risks.
Affected Version(s)
Spring Micrometer 1.17.0 - 1.17.0
Spring Micrometer 1.17.0 - 1.17.0
Spring Micrometer 1.16.0 - 1.16.6