Vulnerability Description
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://spring.io/security/cve-2026-40983
- https://access.redhat.com/errata/RHSA-2026:36839
- https://access.redhat.com/errata/RHSA-2026:41951
- https://access.redhat.com/errata/RHSA-2026:50848
- https://access.redhat.com/errata/RHSA-2026:50849
- https://access.redhat.com/errata/RHSA-2026:54435
- https://access.redhat.com/security/cve/CVE-2026-40983
- https://bugzilla.redhat.com/show_bug.cgi?id=2486697
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40983.json
FAQ
What is CVE-2026-40983?
CVE-2026-40983 is a vulnerability with a CVSS score of 7.5 (HIGH). In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 thr...
How severe is CVE-2026-40983?
CVE-2026-40983 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40983?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.