PatchSiren cyber security CVE debrief
CVE-2026-40984 Spring CVE debrief
Micrometer users should assess exposure to denial-of-service (DoS) conditions via specially crafted HTTP requests. Affected versions include micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17 and micrometer-jetty11 and micrometer-jetty12 with similar version ranges. Defenders should verify inventory, review vendor remediation, and apply compensating controls.
- Vendor
- Spring
- Product
- Micrometer
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-09
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-06-09
- Advisory updated
- 2026-09-14
Who should care
Defenders responsible for systems using Micrometer, particularly those using affected versions, should assess exposure and prioritize remediation. This includes operators managing affected systems, platform administrators, vulnerability management teams, and security teams responsible for monitoring and incident response. These stakeholders should verify inventory, review vendor guidance, and apply necessary patches or mitigations to prevent potential DoS.
Why it matters
CVE-2026-40984 is a denial-of-service (DoS) vulnerability in Micrometer that defenders should address by verifying exposure, prioritizing remediation, and applying compensating controls as needed.
- Potential disruption of service due to DoS condition
- Need for verification of affected versions in inventory
- Priority for applying patches or mitigations
- Potential for increased monitoring and exception tracking
Technical summary
Micrometer, a metrics library for Java and other languages, is vulnerable to a denial-of-service (DoS) condition. Specifically crafted HTTP requests can cause a DoS condition in affected versions of micrometer-core, micrometer-jetty11, and micrometer-jetty12. This vulnerability impacts the availability of services using affected Micrometer versions, potentially leading to service disruptions. Defenders should assess exposure and prioritize remediation based on the severity of potential impact and likelihood of exploitation.
Defensive priority
Defenders should prioritize verification of affected versions in their inventory and apply patches or mitigations as available.
Recommended defensive actions
- Verify affected Micrometer versions in inventory
- Review and apply vendor patches or mitigations
- Monitor for suspicious HTTP requests
- Consider compensating controls for unpatched systems
- Review system logs for potential exploitation attempts
- Prioritize patching or mitigating based on exposure assessment
- Document verification and remediation efforts for audit purposes
Evidence notes
The CVE record and NVD entry provide details on the vulnerability and affected versions. Vendor advisories and errata are available for Red Hat products. Defenders should verify inventory, review vendor remediation, and apply compensating controls as needed. Evidence limits suggest focusing on CVE and NVD details, with additional review of vendor advisories for specific product impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40984 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40984
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40984 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40984
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://spring.io/security/cve-2026-40984
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:36839
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:37390
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:41951
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:50848
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:50849
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:54435
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:62260
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.