An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers.
Micrometer Tracing 1.7.0
Micrometer Tracing 1.6.0 - 1.6.6
Micrometer Tracing 1.5.0 - 1.5.12
Micrometer Tracing 1.4.13 and earlier
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-59323 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-21 10:16
Updated : 2026-08-28 18:47
NVD link : CVE-2026-59323
Mitre link : CVE-2026-59323
CVE.ORG link : CVE-2026-59323
JSON object : View
Products Affected
No product.
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
