CVE-2026-40984: Red Hat Amq Broker 7.13.6
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17. micrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18. micrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.
Affected products
- Red Hat Red Hat Amq Broker 7.13.6
- Red Hat Red Hat Amq Broker 7.14.1
- Red Hat Red Hat Amq Clients
- Red Hat Red Hat Build Of Apache Camel - Hawtio 4
- Red Hat Red Hat Build Of Apache Camel 4.18.1.p1 For Spring Boot 3.5.16
- Red Hat Red Hat Build Of Apache Camel 4.18 For Quarkus 3.33
- Red Hat Red Hat Build Of Apache Camel 4 For Quarkus 3
- Red Hat Red Hat Build Of Apicurio Registry 3
- Red Hat Red Hat Build Of Debezium 3
- Red Hat Red Hat Build Of Keycloak 26.6: before 26.6.5-1 (fixed in 26.6.5-1); before 26.6-11 (fixed in 26.6-11)
- Red Hat Red Hat Build Of Keycloak 26.6.5
- Red Hat Red Hat Build Of Optaplanner 8
- Red Hat Red Hat Data Grid 8.6.2
- Red Hat Red Hat Fuse 7
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat Red Hat Openshift Ai Rhoai
- Red Hat Red Hat Openshift Dev Spaces
- Red Hat Red Hat Openshift Dev Spaces 3.30: before 1787759145 (fixed in 1787759145); before 1787759723 (fixed in 1787759723)
- Red Hat Red Hat Process Automation 7
- Red Hat Streams For Apache Kafka 2
- Red Hat Streams For Apache Kafka 3.2.1
- Spring Micrometer: from 1.16.0, before 1.16.5.1 (fixed in 1.16.5.1); from 1.15.0, before 1.15.11.1 (fixed in 1.15.11.1); from 1.14.0, before 1.14.16 (fixed in 1.14.16); from 1.13.0, before 1.13.19 (fixed in 1.13.19); from 1.9.0, before 1.9.18 (fixed in 1.9.18); from 1.16.0, before 1.16.6 (fixed in 1.16.6); …
Published 2026-06-09. Last modified 2026-09-14.