{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-59323","assignerOrgId":"dcf2e128-44bd-42ed-91e8-88f912c1401d","state":"PUBLISHED","assignerShortName":"vmware","dateReserved":"2026-07-04T18:14:10.167Z","datePublished":"2026-08-21T10:01:05.831Z","dateUpdated":"2026-08-27T18:04:50.627Z"},"containers":{"cna":{"providerMetadata":{"orgId":"dcf2e128-44bd-42ed-91e8-88f912c1401d","shortName":"vmware","dateUpdated":"2026-08-27T18:04:50.627Z"},"title":"Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability","problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-770 Allocation of Resources Without Limits or Throttling","type":"CWE"}]}],"impacts":[{"descriptions":[{"lang":"en","value":"An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers."}]}],"affected":[{"vendor":"Spring","product":"Micrometer Tracing","versions":[{"status":"affected","version":"1.7.0","versionType":"custom"},{"status":"affected","version":"1.6.0","lessThanOrEqual":"1.6.6","versionType":"custom"},{"status":"affected","version":"1.5.0","lessThanOrEqual":"1.5.12","versionType":"custom"},{"status":"affected","version":"0","lessThanOrEqual":"1.4.13","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers.\nMicrometer Tracing 1.7.0\nMicrometer Tracing 1.6.0 - 1.6.6\nMicrometer Tracing 1.5.0 - 1.5.12\nMicrometer Tracing 1.4.13 and earlier","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers.</p><p>Micrometer Tracing 1.7.0<br/>Micrometer Tracing 1.6.0 - 1.6.6<br/>Micrometer Tracing 1.5.0 - 1.5.12<br/>Micrometer Tracing 1.4.13 and earlier</p>"}]}],"references":[{"url":"https://spring.io/security/cve-2026-59323"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}}],"source":{"discovery":"UNKNOWN"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-770","lang":"en","description":"CWE-770 Allocation of Resources Without Limits or Throttling"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-21T12:03:29.254669Z","id":"CVE-2026-59323","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-21T16:44:48.719Z"}}]}}