SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59296

MEDIUM · CVSS 5.9 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Applications utilizing vulnerable versions of micrometer-registry-statsd or micrometer-core, particularly with Datadog or Etsy StatsD flavors, are susceptible to injection and spoofing attacks due to the handling of untrusted input for metrics data. Attackers can exploit this vulnerability to inject line terminators, enabling them to spoof arbitrary metrics and manipulate log entries, potentially compromising the integrity of monitoring and logging systems. Organizations using these libraries for metrics instrumentation should prioritize remediation to safeguard against potential data integrity issues.

CVE
CVE-2026-59296
Severity
MEDIUM
CVSS
5.9
EPSS
0.20%

Original NVD Description

Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform. Micrometer 1.17.0 Micrometer 1.16.0 - 1.16.6 Micrometer 1.15.0 - 1.15.12 Micrometer 1.14.0 - 1.14.16 Micrometer 1.9.18 and earlier