CVE-2026-40983: CWE-400: Uncontrolled Resource Consumption in Spring Micrometer
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
AI Analysis
Technical Summary
Micrometer versions 1.15.0 through 1.15.11 and 1.16.0 through 1.16.5 contain a vulnerability (CVE-2026-40983) where specially crafted gRPC requests can cause uncontrolled resource consumption, leading to denial-of-service (DoS). This flaw allows remote unauthenticated attackers to disrupt system availability by exhausting CPU, memory, or other resources. The vulnerability is classified under CWE-400 and CWE-770, indicating allocation of resources without limits or throttling. The broad accessibility of gRPC endpoints in typical deployments increases the risk. Red Hat advisory confirms the issue and recommends network access restrictions and disabling gRPC if unnecessary. No official patch or fix is currently available, and remediation level is unknown.
Potential Impact
The vulnerability enables remote unauthenticated attackers to cause a denial-of-service condition by exhausting system resources through specially crafted gRPC requests. This impacts the availability of affected systems running vulnerable Micrometer versions. There is no impact on confidentiality or integrity. The broad exposure of gRPC endpoints in typical deployments increases the risk of service disruption.
Mitigation Recommendations
No official patch or fix is currently confirmed for this vulnerability. To mitigate the risk, restrict network access to Micrometer's gRPC endpoints to trusted clients only. Implement firewall rules to limit inbound connections to the specific ports used by gRPC. If gRPC functionality is not essential, consider disabling it entirely to eliminate the attack vector. Note that changes to network configurations or service settings may require service restarts, potentially impacting availability during transition.
CVE-2026-40983: CWE-400: Uncontrolled Resource Consumption in Spring Micrometer
Description
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
CVSS v3.1
Score 7.5high
Affected software
Spring
Micrometer
pkg:maven/io.micrometer/micrometer-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Micrometer versions 1.15.0 through 1.15.11 and 1.16.0 through 1.16.5 contain a vulnerability (CVE-2026-40983) where specially crafted gRPC requests can cause uncontrolled resource consumption, leading to denial-of-service (DoS). This flaw allows remote unauthenticated attackers to disrupt system availability by exhausting CPU, memory, or other resources. The vulnerability is classified under CWE-400 and CWE-770, indicating allocation of resources without limits or throttling. The broad accessibility of gRPC endpoints in typical deployments increases the risk. Red Hat advisory confirms the issue and recommends network access restrictions and disabling gRPC if unnecessary. No official patch or fix is currently available, and remediation level is unknown.
Potential Impact
The vulnerability enables remote unauthenticated attackers to cause a denial-of-service condition by exhausting system resources through specially crafted gRPC requests. This impacts the availability of affected systems running vulnerable Micrometer versions. There is no impact on confidentiality or integrity. The broad exposure of gRPC endpoints in typical deployments increases the risk of service disruption.
Mitigation Recommendations
No official patch or fix is currently confirmed for this vulnerability. To mitigate the risk, restrict network access to Micrometer's gRPC endpoints to trusted clients only. Implement firewall rules to limit inbound connections to the specific ports used by gRPC. If gRPC functionality is not essential, consider disabling it entirely to eliminate the attack vector. Note that changes to network configurations or service settings may require service restarts, potentially impacting availability during transition.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- vmware
- Date Reserved
- 2026-04-16T02:19:04.616Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-40983","vendor":"Red Hat"}]
Threat ID: 6a279b29e29bf47b503573b5
Added to database: 06/09/2026, 04:48:41 UTC
Last enriched: 08/16/2026, 14:16:41 UTC
Last updated: 09/14/2026, 12:32:37 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.