micrometer-core is vulnerable to Denial of Service (DoS)
59
Medium Risk
micrometer-core MicrometerHttpClientInterceptor never removes tracking state when an async HTTP request fails before a response, such as on connection reset or timeout. Sustained failures leak heap until the application crashes. This requires Micrometer instrumentation of Apache HttpAsyncClient 4.x or 5.x. The patch releases interceptor state on pre-response failures.
You are affected if you are using a version that falls within the vulnerable range and Apache HttpAsyncClient is instrumented with MicrometerHttpClientInterceptor.
micrometer-core is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.16.6 and 1.17.0 - 1.17.0.
Upgrade the io.micrometer:micrometer-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant