{"api_version":"1","generated_at":"2026-08-21T19:13:34+00:00","cve":"CVE-2026-59323","urls":{"html":"https://cve.report/CVE-2026-59323","api":"https://cve.report/api/cve/CVE-2026-59323.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-59323","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-59323"},"summary":{"title":"Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability","description":"An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers.\n\n\n\nSpecifically, an application is vulnerable when all the following are true:\n\n  *  The application uses a vulnerable version of io.micrometer:micrometer-tracing-bridge-brave.\n  *  W3C propagation is active (either configured manually or active by default, such as in Spring Boot 3.x+).\n  *  Baggage propagation is enabled (which is the default in Spring Boot 3.x+) and a baggage manager (such as BraveBaggageManager) is configured to handle baggage fields.\n  *  The application processes requests or messages from untrusted sources with baggage headers which it normally should not, see:  https://www.w3.org/TR/trace-context/#security-considerations .\n  *  Network components including the (HTTP) server that receives the request do not limit the header size or the limit is high enough to cause issues.\n\n\n\n\nThe last two points are very important: normally this should not affect applications because they should not receive untrusted and unlimited input for baggage.\n\n  *  The application processes requests or messages from untrusted sources with baggage headers.\n\n\n\n\nWhen extracting baggage from the W3C baggage header, incoming entries are parsed without enforcing limits on the number of entries or header size as mandated by the W3C Baggage specification. An attacker can send requests or messages with artificially inflated baggage headers containing many key-value pairs, causing unconditional BaggageField allocations per entry. This leads to garbage collection pressure, high CPU usage, and potential application crash via OutOfMemoryError.","state":"PUBLISHED","assigner":"vmware","published_at":"2026-08-21 10:16:38","updated_at":"2026-08-21 17:16:32"},"problem_types":["CWE-770","CWE-770 CWE-770 Allocation of Resources Without Limits or Throttling"],"metrics":[{"version":"3.1","source":"security@vmware.com","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"}}],"references":[{"url":"https://spring.io/security/cve-2026-59323","name":"https://spring.io/security/cve-2026-59323","refsource":"security@vmware.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59323","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59323","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"VMware","product":"Spring","version":"affected 1.7.0 - 1.7.0 1.7.0.1 Enterprise Support Only","platforms":[]},{"source":"CNA","vendor":"VMware","product":"Spring","version":"affected 1.7.0 - 1.7.0 1.7.1 OSS","platforms":[]},{"source":"CNA","vendor":"VMware","product":"Spring","version":"affected 1.6.0 - 1.6.6 1.6.6.1 enterprise support only","platforms":[]},{"source":"CNA","vendor":"VMware","product":"Spring","version":"affected 1.6.0 - 1.6.6 1.6.7 oss","platforms":[]},{"source":"CNA","vendor":"VMware","product":"Spring","version":"affected 1.5.0 - 1.5.12 1.5.13 enterprise support only","platforms":[]},{"source":"CNA","vendor":"VMware","product":"Spring","version":"affected 1.4.13 and earlier 1.4.14 enterprise support only","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-59323","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-21T12:03:29.254669Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-770","description":"CWE-770 Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-21T16:44:48.719Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"affected","packageName":"Micrometer Tracing","product":"Spring","vendor":"VMware","versions":[{"lessThan":"1.7.0.1","status":"affected","version":"1.7.0 - 1.7.0","versionType":"Enterprise Support Only"},{"lessThan":"1.7.1","status":"affected","version":"1.7.0 - 1.7.0","versionType":"OSS"},{"lessThan":"1.6.6.1","status":"affected","version":"1.6.0 - 1.6.6","versionType":"enterprise support only"},{"lessThan":"1.6.7","status":"affected","version":"1.6.0 - 1.6.6","versionType":"oss"},{"lessThan":"1.5.13","status":"affected","version":"1.5.0 - 1.5.12","versionType":"enterprise support only"},{"lessThan":"1.4.14","status":"affected","version":"1.4.13 and earlier","versionType":"enterprise support only"}]}],"datePublic":"2026-08-20T09:55:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming&nbsp;<code>baggage</code>&nbsp;headers.</p><p>Specifically, an application is vulnerable when all the following are true:</p><ul><li>The application uses a vulnerable version of&nbsp;<code>io.micrometer:micrometer-tracing-bridge-brave</code>.</li><li>W3C propagation is active (either configured manually or active by default, such as in Spring Boot 3.x+).</li><li>Baggage propagation is enabled (which is the default in Spring Boot 3.x+) and a baggage manager (such as&nbsp;<code>BraveBaggageManager</code>) is configured to handle baggage fields.</li><li>The application processes requests or messages from untrusted sources with&nbsp;<code>baggage</code>&nbsp;headers which it normally should not, see:&nbsp;<a href=\"https://www.w3.org/TR/trace-context/#security-considerations\">https://www.w3.org/TR/trace-context/#security-considerations</a>.</li><li>Network components including the (HTTP) server that receives the request do not limit the header size or the limit is high enough to cause issues.</li></ul><p>The last two points are very important: normally this should not affect applications because they should not receive untrusted and unlimited input for baggage.</p><ul><li>The application processes requests or messages from untrusted sources with&nbsp;<code>baggage</code>&nbsp;headers.</li></ul><p>When extracting baggage from the W3C&nbsp;<code>baggage</code>&nbsp;header, incoming entries are parsed without enforcing limits on the number of entries or header size as mandated by the W3C Baggage specification. An attacker can send requests or messages with artificially inflated&nbsp;<code>baggage</code>&nbsp;headers containing many key-value pairs, causing unconditional&nbsp;<code>BaggageField</code>&nbsp;allocations per entry. This leads to garbage collection pressure, high CPU usage, and potential application crash via&nbsp;<code>OutOfMemoryError</code>.</p>"}],"value":"An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers.\n\n\n\nSpecifically, an application is vulnerable when all the following are true:\n\n  *  The application uses a vulnerable version of io.micrometer:micrometer-tracing-bridge-brave.\n  *  W3C propagation is active (either configured manually or active by default, such as in Spring Boot 3.x+).\n  *  Baggage propagation is enabled (which is the default in Spring Boot 3.x+) and a baggage manager (such as BraveBaggageManager) is configured to handle baggage fields.\n  *  The application processes requests or messages from untrusted sources with baggage headers which it normally should not, see:  https://www.w3.org/TR/trace-context/#security-considerations .\n  *  Network components including the (HTTP) server that receives the request do not limit the header size or the limit is high enough to cause issues.\n\n\n\n\nThe last two points are very important: normally this should not affect applications because they should not receive untrusted and unlimited input for baggage.\n\n  *  The application processes requests or messages from untrusted sources with baggage headers.\n\n\n\n\nWhen extracting baggage from the W3C baggage header, incoming entries are parsed without enforcing limits on the number of entries or header size as mandated by the W3C Baggage specification. An attacker can send requests or messages with artificially inflated baggage headers containing many key-value pairs, causing unconditional BaggageField allocations per entry. This leads to garbage collection pressure, high CPU usage, and potential application crash via OutOfMemoryError."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"providerMetadata":{"dateUpdated":"2026-08-21T10:01:05.831Z","orgId":"dcf2e128-44bd-42ed-91e8-88f912c1401d","shortName":"vmware"},"references":[{"url":"https://spring.io/security/cve-2026-59323"}],"source":{"discovery":"UNKNOWN"},"title":"Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability","x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"dcf2e128-44bd-42ed-91e8-88f912c1401d","assignerShortName":"vmware","cveId":"CVE-2026-59323","datePublished":"2026-08-21T10:01:05.831Z","dateReserved":"2026-07-04T18:14:10.167Z","dateUpdated":"2026-08-21T16:44:48.719Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-21 10:16:38","lastModifiedDate":"2026-08-21 17:16:32","problem_types":["CWE-770","CWE-770 CWE-770 Allocation of Resources Without Limits or Throttling"],"metrics":{"cvssMetricV31":[{"source":"security@vmware.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-21T12:03:29.254669Z","id":"CVE-2026-59323","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"59323","Ordinal":"1","Title":"Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vuln","CVE":"CVE-2026-59323","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"59323","Ordinal":"1","NoteData":"An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers.\n\n\n\nSpecifically, an application is vulnerable when all the following are true:\n\n  *  The application uses a vulnerable version of io.micrometer:micrometer-tracing-bridge-brave.\n  *  W3C propagation is active (either configured manually or active by default, such as in Spring Boot 3.x+).\n  *  Baggage propagation is enabled (which is the default in Spring Boot 3.x+) and a baggage manager (such as BraveBaggageManager) is configured to handle baggage fields.\n  *  The application processes requests or messages from untrusted sources with baggage headers which it normally should not, see:  https://www.w3.org/TR/trace-context/#security-considerations .\n  *  Network components including the (HTTP) server that receives the request do not limit the header size or the limit is high enough to cause issues.\n\n\n\n\nThe last two points are very important: normally this should not affect applications because they should not receive untrusted and unlimited input for baggage.\n\n  *  The application processes requests or messages from untrusted sources with baggage headers.\n\n\n\n\nWhen extracting baggage from the W3C baggage header, incoming entries are parsed without enforcing limits on the number of entries or header size as mandated by the W3C Baggage specification. An attacker can send requests or messages with artificially inflated baggage headers containing many key-value pairs, causing unconditional BaggageField allocations per entry. This leads to garbage collection pressure, high CPU usage, and potential application crash via OutOfMemoryError.","Type":"Description","Title":"Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vuln"}]}}}