Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform.
Micrometer 1.17.0
Micrometer 1.16.0 - 1.16.6
Micrometer 1.15.0 - 1.15.12
Micrometer 1.14.0 - 1.14.16
Micrometer 1.9.18 and earlier
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-59296 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-21 11:17
Updated : 2026-08-28 18:47
NVD link : CVE-2026-59296
Mitre link : CVE-2026-59296
CVE.ORG link : CVE-2026-59296
JSON object : View
Products Affected
No product.
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
