Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40983

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

A flaw was found in Micrometer. A remote attacker can provide specially crafted gRPC (gRPC Remote Procedure Call) requests, which may lead to a denial-of-service (DoS) condition. This vulnerability allows an attacker to disrupt the availability of the affected system.

Отчет

This is an Important denial-of-service vulnerability in Micrometer, as a remote unauthenticated attacker can disrupt the availability of affected systems by sending specially crafted gRPC requests. The broad accessibility of gRPC endpoints in typical deployments contributes to the elevated risk, allowing for significant service interruption.

Меры по смягчению последствий

To mitigate this issue, restrict network access to services exposing Micrometer's gRPC endpoints to trusted clients only. Implement firewall rules to limit inbound connections to the specific ports used by gRPC. If gRPC functionality is not essential for the deployment, consider disabling it entirely to eliminate the attack vector. Any changes to network configurations or service settings may require a service restart to take effect, potentially impacting availability during the transition.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7micrometer-coreAffected
Red Hat AMQ Clientsmicrometer-coreAffected
Red Hat build of Apache Camel 4 for Quarkus 3micrometer-coreAffected
Red Hat build of Apache Camel for Spring Boot 4micrometer-coreNot affected
Red Hat build of Apache Camel - HawtIO 4micrometer-coreAffected
Red Hat build of Apicurio Registry 3micrometer-coreFix deferred
Red Hat build of Debezium 3micrometer-coreNot affected
Red Hat Build of Keycloakmicrometer-coreAffected
Red Hat Build of Keycloakrhbk/keycloak-rhel9Affected
Red Hat Build of Keycloakrhbk/keycloak-rhel9-operatorAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2486697micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

CVSS3: 7.5
github
около 2 месяцев назад

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость java-библиотеки Micrometer фреймворка создания веб-приложений Spring Boot, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3