VMwareCVE-2026-59295
VMware Micrometer: denial of service
Medium5.9CVE-2026-59295 · Published Aug 24, 2026 · updated Aug 28, 2026
It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) condition due to an unbounded memory leak. Micrometer 1.17.0 Micrometer 1.16.0 - 1.16.6 Micrometer 1.15.0 - 1.15.12 Micrometer 1.14.0 - 1.14.16 Micrometer 1.9.18 and earlier
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Micrometer Product | <= 1.17.0 | No fix yet |
| >= 1.16.0, <= 1.16.6 | No fix yet | |
| >= 1.15.0, <= 1.15.12 | No fix yet | |
| >= 1.14.0, <= 1.14.16 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
More VMware advisories
All VMware| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 26 | Spring Data JPA's Sort validation can be bypassed | Medium4.8 | No fix yet |
| Aug 26 | VMware Spring Security: improper authorization | High7.4 | No fix yet |
| Aug 26 | VMware Spring Cloud Config: missing authentication | Medium6.8 | No fix yet |
| Aug 26 | VMware Spring Cloud Config: race condition | High7.2 | No fix yet |
| Aug 25 | VMware Spring Security: authentication bypass | High7.4 | No fix yet |
| Aug 25 | Improper handling of case sensitivity | High8.7 | 78.16.0+1 more |