VMwareCVE-2026-59323
VMware Micrometer Tracing: denial of service
Medium5.3CVE-2026-59323 · Published Aug 21, 2026 · updated Aug 28, 2026
An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers. Micrometer Tracing 1.7.0 Micrometer Tracing 1.6.0 - 1.6.6 Micrometer Tracing 1.5.0 - 1.5.12 Micrometer Tracing 1.4.13 and earlier
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Micrometer Tracing Product | <= 1.7.0 | No fix yet |
| >= 1.6.0, <= 1.6.6 | No fix yet | |
| >= 1.5.0, <= 1.5.12 | No fix yet | |
| <= 1.4.13 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-770
More VMware advisories
All VMware| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 24 | VMware Micrometer: denial of service | Medium5.9 | No fix yet |
| Aug 21 | VMware Spring AI: denial of service | High7.5 | No fix yet |
| Aug 21 | VMware Spring AI: resource exposure | Medium4.2 | No fix yet |
| Aug 21 | VMware Spring AI: privilege escalation | Medium6.5 | No fix yet |
| Aug 21 | VMware Micrometer: injection | Medium5.9 | No fix yet |
| Aug 21 | VMware BOSH CLI: command injection | High7.5 | 2.840.0 |