Spring Micrometer DoS flaws patched
Multiple denial-of-service vulnerabilities in Spring Micrometer Core and Jetty integrations allow remote attackers to disrupt services across versions 1.9.x through 1.16.x.
CERT-FR has disclosed two denial-of-service vulnerabilities affecting Spring Micrometer, a widely-used metrics instrumentation library for JVM-based applications. The flaws, tracked as CVE-2026-40983 and CVE-2026-40984, impact Micrometer Core and its Jetty11/Jetty12 integration modules across multiple release branches. Vulnerable versions span from 1.9.x through 1.16.x, with the earliest affected release being 1.9.0 and fixes available in 1.9.18, 1.13.19, 1.14.16, 1.15.12, and 1.16.6.
The vulnerabilities enable remote attackers to trigger denial-of-service conditions without authentication, though technical details of the attack vectors remain undisclosed. Organizations using Spring Micrometer for application metrics collection should prioritize patching, particularly in internet-facing environments where the remote exploitation vector presents elevated risk. Spring has released patches for all affected branches, and administrators are advised to consult the vendor security bulletins for specific upgrade guidance.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0702
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free