CVE-2026-59323

Summary

An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers. Micrometer Tracing 1.7.0 Micrometer Tracing 1.6.0 - 1.6.6 Micrometer Tracing 1.5.0 - 1.5.12 Micrometer Tracing 1.4.13 and earlier

Affected Software

VendorProductVersion RangeStatus
SpringMicrometer Tracing1.7.0affected
SpringMicrometer Tracing1.6.0 <= 1.6.6affected
SpringMicrometer Tracing1.5.0 <= 1.5.12affected
SpringMicrometer Tracing0 <= 1.4.13affected

Weaknesses

  • CWE-770 Allocation of Resources Without Limits or Throttling

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References