Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33013

Опубликовано: 20 мар. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., authors[1].name followed by authors[0].name). This issue has been fixed in versions 4.10.16 and 3.10.5.

A flaw was found in Micronaut Framework, specifically within the micronaut-core component. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending crafted indexed form parameters. The flaw occurs because the framework does not correctly handle descending array index order during form-urlencoded body binding, leading to a non-terminating loop, CPU exhaustion, and OutOfMemoryError.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4jkube-kit-micronautNot affected
Red Hat Fuse 7bolt-micronautOut of support scope
Red Hat Fuse 7jkube-kit-micronautOut of support scope
Red Hat Fuse 7micronaut-aopOut of support scope
Red Hat Fuse 7micronaut-buffer-nettyOut of support scope
Red Hat Fuse 7micronaut-contextOut of support scope
Red Hat Fuse 7micronaut-coreOut of support scope
Red Hat Fuse 7micronaut-core-reactiveOut of support scope
Red Hat Fuse 7micronaut-httpOut of support scope
Red Hat Fuse 7micronaut-http-clientOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1285
https://bugzilla.redhat.com/show_bug.cgi?id=2449457micronaut-core: Micronaut Framework: Micronaut Framework: Denial of Service via crafted form parameters

EPSS

Процентиль: 45%
0.00595
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
5 месяцев назад

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., authors[1].name followed by authors[0].name). This issue has been fixed in versions 4.10.16 and 3.10.5.

github
5 месяцев назад

Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices

EPSS

Процентиль: 45%
0.00595
Низкий

6.5 Medium

CVSS3