Injection Vulnerability in Micrometer Registry StatsD and Core Products
CVE-2026-59296

5.9MEDIUM

Key Information:

Vendor

Vmware

Vendor
CVE Published:
21 August 2026

What is CVE-2026-59296?

This vulnerability arises when untrusted, non-normalized input, such as metric names and tag values, is used within the Micrometer Registry StatsD and Core products. When applications utilize these components without proper sanitization of newline characters, they open themselves up to injection attacks. Specifically, for the StatsD registry employing Datadog or Etsy flavors, the newline-delimited protocol makes them susceptible to line-protocol injection attacks. Furthermore, the LoggingMeterRegistry can experience metric and log spoofing due to how output is treated in logs. Attackers can exploit this by injecting line terminators, enabling them to spoof arbitrary metrics or disrupt log integrity, leading to serious security risks.

Affected Version(s)

Spring Micrometer 1.17.0 - 1.17.0

Spring Micrometer 1.17.0 - 1.17.0

Spring Micrometer 1.16.0 - 1.16.6

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.