PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40984 Spring CVE debrief

Micrometer users should assess exposure to denial-of-service (DoS) conditions via specially crafted HTTP requests. Affected versions include micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17 and micrometer-jetty11 and micrometer-jetty12 with similar version ranges. Defenders should verify inventory, review vendor remediation, and apply compensating controls.

Vendor
Spring
Product
Micrometer
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-09
Original CVE updated
2026-09-14
Advisory published
2026-06-09
Advisory updated
2026-09-14

Who should care

Defenders responsible for systems using Micrometer, particularly those using affected versions, should assess exposure and prioritize remediation. This includes operators managing affected systems, platform administrators, vulnerability management teams, and security teams responsible for monitoring and incident response. These stakeholders should verify inventory, review vendor guidance, and apply necessary patches or mitigations to prevent potential DoS.

Why it matters

CVE-2026-40984 is a denial-of-service (DoS) vulnerability in Micrometer that defenders should address by verifying exposure, prioritizing remediation, and applying compensating controls as needed.

  • Potential disruption of service due to DoS condition
  • Need for verification of affected versions in inventory
  • Priority for applying patches or mitigations
  • Potential for increased monitoring and exception tracking

Technical summary

Micrometer, a metrics library for Java and other languages, is vulnerable to a denial-of-service (DoS) condition. Specifically crafted HTTP requests can cause a DoS condition in affected versions of micrometer-core, micrometer-jetty11, and micrometer-jetty12. This vulnerability impacts the availability of services using affected Micrometer versions, potentially leading to service disruptions. Defenders should assess exposure and prioritize remediation based on the severity of potential impact and likelihood of exploitation.

Defensive priority

Defenders should prioritize verification of affected versions in their inventory and apply patches or mitigations as available.

Recommended defensive actions

  • Verify affected Micrometer versions in inventory
  • Review and apply vendor patches or mitigations
  • Monitor for suspicious HTTP requests
  • Consider compensating controls for unpatched systems
  • Review system logs for potential exploitation attempts
  • Prioritize patching or mitigating based on exposure assessment
  • Document verification and remediation efforts for audit purposes

Evidence notes

The CVE record and NVD entry provide details on the vulnerability and affected versions. Vendor advisories and errata are available for Red Hat products. Defenders should verify inventory, review vendor remediation, and apply compensating controls as needed. Evidence limits suggest focusing on CVE and NVD details, with additional review of vendor advisories for specific product impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-40984 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-40984

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-40984 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40984

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://spring.io/security/cve-2026-40984

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:36839

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:37390

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:41951

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:50848

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:50849

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:54435

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:62260

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.