Spring disclosed two high-severity denial-of-service vulnerabilities in Micrometer server instrumentation: CVE-2026-40984 affecting HTTP server instrumentations and CVE-2026-40983 affecting gRPC server instrumentation. The HTTP issue can be triggered by specially crafted HTTP requests in applications using vulnerable versions of micrometer-core, micrometer-jetty11, or micrometer-jetty12 with HTTP server instrumentation and metrics recording enabled. The gRPC issue can be triggered by specially crafted gRPC requests when applications use vulnerable io.micrometer:micrometer-core releases together with ObservationRegistry, metric-producing observation handlers, and ObservationGrpcServerInterceptor.
Affected versions include Micrometer 1.16.0 through 1.16.5 and 1.15.0 through 1.15.11, with the HTTP flaw also spanning additional older supported and unsupported release lines. Spring released fixes for open-source users in Micrometer 1.16.6 and 1.15.12, while enterprise-supported fixes for the HTTP issue are available in 1.14.16, 1.13.19, and 1.9.18. The vulnerabilities were responsibly reported by Yu Bao of PayPal, and the Canadian Centre for Cyber Security urged administrators to review Spring’s advisories and apply the necessary updates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-08, the Canadian Centre for Cyber Security published advisory AV26-558 highlighting Spring's Micrometer-related vulnerabilities CVE-2026-40983 and CVE-2026-40984. The notice urged users and administrators to review the linked advisories and apply the necessary updates.
Spring advised users to upgrade to Micrometer 1.16.6 or 1.15.12 to remediate the disclosed vulnerabilities. For CVE-2026-40984, enterprise-supported fixes were also made available in versions 1.14.16, 1.13.19, and 1.9.18.
On 2026-06-08, Spring published security advisories for two high-severity denial-of-service flaws in Micrometer: CVE-2026-40983 affecting gRPC server instrumentation and CVE-2026-40984 affecting HTTP server instrumentations. The advisories identified affected versions and described the conditions required to trigger the DoS issues.
Spring's advisories state that the Micrometer denial-of-service vulnerabilities were responsibly reported by Yu Bao of PayPal. The references do not provide a specific date for when the report was made.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcespring.io
Open sourcespring.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.