Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33013

Опубликовано: 20 мар. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., authors[1].name followed by authors[0].name). This issue has been fixed in versions 4.10.16 and 3.10.5.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:objectcomputing:micronaut:*:*:*:*:*:*:*:*
Версия до 3.10.5 (исключая)
cpe:2.3:a:objectcomputing:micronaut:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.10.16 (исключая)

EPSS

Процентиль: 45%
0.00595
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 6.5
redhat
5 месяцев назад

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., authors[1].name followed by authors[0].name). This issue has been fixed in versions 4.10.16 and 3.10.5.

github
5 месяцев назад

Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices

EPSS

Процентиль: 45%
0.00595
Низкий

7.5 High

CVSS3

Дефекты

CWE-835