Skip to content
VMwareCVE-2026-59323

VMware Micrometer Tracing: denial of service

Medium5.3CVE-2026-59323 · Published Aug 21, 2026 · updated Aug 28, 2026

An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers. Micrometer Tracing 1.7.0 Micrometer Tracing 1.6.0 - 1.6.6 Micrometer Tracing 1.5.0 - 1.5.12 Micrometer Tracing 1.4.13 and earlier

VMware advisory

Affected versions

PackageAffectedFixed in
Micrometer Tracing
Product
<= 1.7.0No fix yet
>= 1.6.0, <= 1.6.6No fix yet
>= 1.5.0, <= 1.5.12No fix yet
<= 1.4.13No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-770

More VMware advisories

All VMware
Advisory
VMware Micrometer: denial of service
Medium5.9Aug 24
VMware Spring AI: denial of service
High7.5Aug 21
VMware Spring AI: resource exposure
Medium4.2Aug 21
VMware Spring AI: privilege escalation
Medium6.5Aug 21
VMware Micrometer: injection
Medium5.9Aug 21
VMware BOSH CLI: command injection
High7.5Aug 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.