Intel

AIKIDO-2026-194896

spring-cloud-sleuth-instrumentation is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource ConsumptionCVE-2026-41708 Published Today

80

High Risk

This Affects:

javaspring-cloud-sleuth-instrumentation
3.1.0 - 3.1.13
Fixed in 3.1.14
Are you affected? Scan for Free

TL;DR

Spring Cloud Sleuth contains a denial-of-service vulnerability in its Spring TX instrumentation. Applications using vulnerable versions of spring-cloud-sleuth-instrumentation with Spring TX instrumentation enabled may be susceptible to specially crafted requests that trigger excessive resource consumption, potentially causing service degradation or application unavailability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and if Spring TX instrumentation is not disabled.

Background info

spring-cloud-sleuth-instrumentation is vulnerable to Uncontrolled Resource Consumption in versions 3.1.0 - 3.1.13.

How to fix this

Upgrade the org.springframework.cloud:spring-cloud-sleuth-instrumentation library to a patch version.