CVE-2026-59296 (GCVE-0-2026-59296)
Vulnerability from cvelistv5
Published
2026-08-21 10:47
Modified
2026-08-27 17:57
Summary
Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform. Micrometer 1.17.0 Micrometer 1.16.0 - 1.16.6 Micrometer 1.15.0 - 1.15.12 Micrometer 1.14.0 - 1.14.16 Micrometer 1.9.18 and earlier
Impacted products
Vendor Product Version
Spring Micrometer Version: 1.17.0   <
Version: 1.16.0   <
Version: 1.15.0   <
Version: 1.14.0   <
Version: 0   <
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-59296",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-21T11:55:29.457945Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-74",
                "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-21T16:44:12.342Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Micrometer",
          "vendor": "Spring",
          "versions": [
            {
              "status": "affected",
              "version": "1.17.0",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "1.16.6",
              "status": "affected",
              "version": "1.16.0",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "1.15.12",
              "status": "affected",
              "version": "1.15.0",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "1.14.16",
              "status": "affected",
              "version": "1.14.0",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "1.9.18",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eUsing untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform.\u003c/p\u003e\u003cp\u003eMicrometer 1.17.0\u003cbr/\u003eMicrometer 1.16.0 - 1.16.6\u003cbr/\u003eMicrometer 1.15.0 - 1.15.12\u003cbr/\u003eMicrometer 1.14.0 - 1.14.16\u003cbr/\u003eMicrometer 1.9.18 and earlier\u003c/p\u003e"
            }
          ],
          "value": "Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform.\nMicrometer 1.17.0\nMicrometer 1.16.0 - 1.16.6\nMicrometer 1.15.0 - 1.15.12\nMicrometer 1.14.0 - 1.14.16\nMicrometer 1.9.18 and earlier"
        }
      ],
      "impacts": [
        {
          "descriptions": [
            {
              "lang": "en",
              "value": "Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform."
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "CWE-117 Improper Output Neutralization for Logs",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-27T17:57:53.054Z",
        "orgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d",
        "shortName": "vmware"
      },
      "references": [
        {
          "url": "https://spring.io/security/cve-2026-59296"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "Micrometer StatsD and Logging meter registries line-protocol and log injection vulnerability"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d",
    "assignerShortName": "vmware",
    "cveId": "CVE-2026-59296",
    "datePublished": "2026-08-21T10:47:25.384Z",
    "dateReserved": "2026-07-04T18:13:34.323Z",
    "dateUpdated": "2026-08-27T17:57:53.054Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-59296\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-08-21T11:55:29.457945Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-74\", \"description\": \"CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-08-21T11:55:35.874Z\"}}], \"cna\": {\"title\": \"Micrometer StatsD and Logging meter registries line-protocol and log injection vulnerability\", \"source\": {\"discovery\": \"UNKNOWN\"}, \"metrics\": [{\"format\": \"CVSS\", \"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.9, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"HIGH\", \"availabilityImpact\": \"NONE\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"NONE\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"vendor\": \"VMware\", \"product\": \"Spring Micrometer\", \"versions\": [{\"status\": \"affected\", \"version\": \"1.17.0 - 1.17.0\"}, {\"status\": \"affected\", \"version\": \"1.16.0 - 1.16.6\"}, {\"status\": \"affected\", \"version\": \"1.15.0 - 1.15.12\"}, {\"status\": \"affected\", \"version\": \"1.14.0 - 1.14.16\"}, {\"status\": \"affected\", \"version\": \"1.9.18 and earlier\"}, {\"status\": \"unaffected\", \"version\": \"1.17.0.1\", \"versionType\": \"enterprise support only\"}, {\"status\": \"unaffected\", \"version\": \"1.17.1\", \"versionType\": \"oss\"}, {\"status\": \"unaffected\", \"version\": \"1.16.6.1\", \"versionType\": \"enterprise support only\"}, {\"status\": \"unaffected\", \"version\": \"1.16.7\", \"versionType\": \"oss\"}, {\"status\": \"unaffected\", \"version\": \"1.15.13\", \"versionType\": \"enterprise support only\"}, {\"status\": \"unaffected\", \"version\": \"1.14.17\", \"versionType\": \"enterprise support only\"}, {\"status\": \"unaffected\", \"version\": \"1.9.19\", \"versionType\": \"enterprise support only\"}], \"defaultStatus\": \"affected\"}], \"datePublic\": \"2026-08-20T10:42:00.000Z\", \"references\": [{\"url\": \"https://spring.io/security/cve-2026-59296\"}], \"x_generator\": {\"engine\": \"Vulnogram 1.0.4\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform. When such unsafe instrumentation is used, the application becomes vulnerable to injection and spoofing attacks because\\u00a0micrometer-registry-statsd\\u00a0and\\u00a0micrometer-core\\u00a0do not sanitize newline characters (\\\\n,\\u00a0\\\\r) by default prior to this fix.\\n\\n  *  For the StatsD registry in\\u00a0micrometer-registry-statsd\\u00a0(when using the\\u00a0Datadog\\u00a0or\\u00a0Etsy\\u00a0flavor), because the StatsD protocol is newline-delimited, this allows for line-protocol injection (cross-metric spoofing).\\n  *  For\\u00a0LoggingMeterRegistry\\u00a0in\\u00a0micrometer-core, because metric output is printed line-by-line to log files, this allows for both metric spoofing (if downstream log-metrics scrapers or parsers ingest the log lines as separate metrics) and general log spoofing.\\n\\n\\n\\n\\nSpecifically, an application is vulnerable when all the following are true:\\n\\n  *  The application uses a vulnerable version of\\u00a0io.micrometer:micrometer-registry-statsd\\u00a0or\\u00a0io.micrometer:micrometer-core.\\n  *  The application uses the\\u00a0Datadog\\u00a0or\\u00a0Etsy\\u00a0flavor of the StatsD registry, or uses\\u00a0LoggingMeterRegistry.\\n  *  The application instruments meters using user-controlled, unvalidated input for metric names, tag keys, or tag values.\\n\\n\\n\\n\\nWhen vulnerable, an attacker can break out of the current metric or log line by injecting line terminators. This allows them to spoof arbitrary metrics (e.g., system load, standard JVM metrics, or other business metrics) across the metrics registry namespace (either directly via StatsD protocol or via downstream log-metric scrapers/parsers), as well as inject arbitrary log entries to spoof general log records.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eUsing untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform. When such unsafe instrumentation is used, the application becomes vulnerable to injection and spoofing attacks because\u0026nbsp;\u003ccode\u003emicrometer-registry-statsd\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003emicrometer-core\u003c/code\u003e\u0026nbsp;do not sanitize newline characters (\u003ccode\u003e\\\\n\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e\\\\r\u003c/code\u003e) by default prior to this fix.\u003c/p\u003e\u003cul\u003e\u003cli\u003eFor the StatsD registry in\u0026nbsp;\u003ccode\u003emicrometer-registry-statsd\u003c/code\u003e\u0026nbsp;(when using the\u0026nbsp;\u003ccode\u003eDatadog\u003c/code\u003e\u0026nbsp;or\u0026nbsp;\u003ccode\u003eEtsy\u003c/code\u003e\u0026nbsp;flavor), because the StatsD protocol is newline-delimited, this allows for line-protocol injection (cross-metric spoofing).\u003c/li\u003e\u003cli\u003eFor\u0026nbsp;\u003ccode\u003eLoggingMeterRegistry\u003c/code\u003e\u0026nbsp;in\u0026nbsp;\u003ccode\u003emicrometer-core\u003c/code\u003e, because metric output is printed line-by-line to log files, this allows for both metric spoofing (if downstream log-metrics scrapers or parsers ingest the log lines as separate metrics) and general log spoofing.\u003c/li\u003e\u003c/ul\u003e\u003cp\u003eSpecifically, an application is vulnerable when all the following are true:\u003c/p\u003e\u003cul\u003e\u003cli\u003eThe application uses a vulnerable version of\u0026nbsp;\u003ccode\u003eio.micrometer:micrometer-registry-statsd\u003c/code\u003e\u0026nbsp;or\u0026nbsp;\u003ccode\u003eio.micrometer:micrometer-core\u003c/code\u003e.\u003c/li\u003e\u003cli\u003eThe application uses the\u0026nbsp;\u003ccode\u003eDatadog\u003c/code\u003e\u0026nbsp;or\u0026nbsp;\u003ccode\u003eEtsy\u003c/code\u003e\u0026nbsp;flavor of the StatsD registry, or uses\u0026nbsp;\u003ccode\u003eLoggingMeterRegistry\u003c/code\u003e.\u003c/li\u003e\u003cli\u003eThe application instruments meters using user-controlled, unvalidated input for metric names, tag keys, or tag values.\u003c/li\u003e\u003c/ul\u003e\u003cp\u003eWhen vulnerable, an attacker can break out of the current metric or log line by injecting line terminators. This allows them to spoof arbitrary metrics (e.g., system load, standard JVM metrics, or other business metrics) across the metrics registry namespace (either directly via StatsD protocol or via downstream log-metric scrapers/parsers), as well as inject arbitrary log entries to spoof general log records.\u003c/p\u003e\", \"base64\": false}]}], \"providerMetadata\": {\"orgId\": \"dcf2e128-44bd-42ed-91e8-88f912c1401d\", \"shortName\": \"vmware\", \"dateUpdated\": \"2026-08-21T10:47:25.384Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2026-59296\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-21T16:44:12.342Z\", \"dateReserved\": \"2026-07-04T18:13:34.323Z\", \"assignerOrgId\": \"dcf2e128-44bd-42ed-91e8-88f912c1401d\", \"datePublished\": \"2026-08-21T10:47:25.384Z\", \"assignerShortName\": \"vmware\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…