# Spring Micrometer DoS flaws patched

Published: 2026-06-08 · Severity: high
Canonical: https://vorant.io/reports/3c038a2c-5150-41f6-a857-7d184a1548d2/spring-micrometer-dos-flaws-patched

> Multiple denial-of-service vulnerabilities in Spring Micrometer Core and Jetty integrations allow remote attackers to disrupt services across versions 1.9.x through 1.16.x.

CERT-FR has disclosed two denial-of-service vulnerabilities affecting Spring Micrometer, a widely-used metrics instrumentation library for JVM-based applications. The flaws, tracked as CVE-2026-40983 and CVE-2026-40984, impact Micrometer Core and its Jetty11/Jetty12 integration modules across multiple release branches. Vulnerable versions span from 1.9.x through 1.16.x, with the earliest affected release being 1.9.0 and fixes available in 1.9.18, 1.13.19, 1.14.16, 1.15.12, and 1.16.6.

The vulnerabilities enable remote attackers to trigger denial-of-service conditions without authentication, though technical details of the attack vectors remain undisclosed. Organizations using Spring Micrometer for application metrics collection should prioritize patching, particularly in internet-facing environments where the remote exploitation vector presents elevated risk. Spring has released patches for all affected branches, and administrators are advised to consult the vendor security bulletins for specific upgrade guidance.

## Mentioned in this report

- Vulnerabilities: CVE-2026-40983, CVE-2026-40984

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0702

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3c038a2c-5150-41f6-a857-7d184a1548d2/spring-micrometer-dos-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
