Intel

AIKIDO-2026-784840

micrometer-tracing-bridge-brave is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-59323 Published 3 days ago

53

Medium Risk

This Affects:

JAVAmicrometer-tracing-bridge-brave
0.0.1 - 1.6.6
Fixed in 1.6.7
1.7.0 - 1.7.0
Fixed in 1.7.1
Are you affected? Scan for Free

TL;DR

micrometer-tracing-bridge-brave allocates unbounded objects when extracting W3C baggage headers. A client who sends many baggage fields can exhaust memory. This is the default in Spring Boot 3.x when W3C and baggage are on. The patch bounds baggage extraction.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and Micrometer Tracing Brave W3C baggage propagation is enabled on untrusted requests.

Background info

micrometer-tracing-bridge-brave is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.6.6 and 1.7.0 - 1.7.0.

How to fix this

Upgrade the io.micrometer:micrometer-tracing-bridge-brave library to the patch version.