SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59323

MEDIUM · CVSS 5.3 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Applications utilizing a vulnerable version of io.micrometer:micrometer-tracing-bridge-brave with W3C baggage propagation enabled are susceptible to denial of service due to unbounded object allocation when processing incoming baggage headers. This vulnerability can be exploited by attackers sending requests with excessively large baggage headers, leading to increased CPU usage and potential application crashes from OutOfMemoryError. Organizations using affected versions, particularly those processing untrusted input, should prioritize patching to mitigate this risk.

CVE
CVE-2026-59323
Severity
MEDIUM
CVSS
5.3
EPSS
0.37%

Original NVD Description

An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers. Micrometer Tracing 1.7.0 Micrometer Tracing 1.6.0 - 1.6.6 Micrometer Tracing 1.5.0 - 1.5.12 Micrometer Tracing 1.4.13 and earlier