CVE-2026-59323: Spring Micrometer Tracing
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers. Micrometer Tracing 1.7.0 Micrometer Tracing 1.6.0 - 1.6.6 Micrometer Tracing 1.5.0 - 1.5.12 Micrometer Tracing 1.4.13 and earlier
Affected products
- Spring Micrometer Tracing: version 1.7.0 only; from 1.6.0, up to and including 1.6.6; from 1.5.0, up to and including 1.5.12; up to and including 1.4.13
Published 2026-08-21. Last modified 2026-08-28.