Intel

AIKIDO-2026-11153

micrometer-jetty12 is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-40984 Published Yesterday

75

High Risk

This Affects:

JAVAmicrometer-jetty12
0.0.0 - 1.13.18
Fixed in 1.13.19
1.14.0 - 1.14.15
Fixed in 1.14.16
1.15.0 - 1.15.11
Fixed in 1.15.12
1.16.0 - 1.16.5
Fixed in 1.16.6
Are you affected? Scan for Free

TL;DR

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

micrometer-jetty12 is vulnerable to Denial of Service (DoS) in versions 0.0.0 - 1.13.18, 1.14.0 - 1.14.15, 1.15.0 - 1.15.11 and 1.16.0 - 1.16.5.

How to fix this

Upgrade the io.micrometer:micrometer-jetty12 library to the patch version.