SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59295

MEDIUM · CVSS 5.9 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Apache HttpAsyncClient (versions 4.x and 5.x) is vulnerable to a memory leak due to the MicrometerHttpClientInterceptor, which fails to release memory for asynchronous requests that encounter errors before receiving a response. This can result in unbounded memory consumption, leading to heap exhaustion and potential OutOfMemoryError crashes. Organizations utilizing this client in environments with high failure rates should prioritize addressing this vulnerability to prevent service disruptions.

CVE
CVE-2026-59295
Severity
MEDIUM
CVSS
5.9
EPSS
0.22%

Original NVD Description

It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) condition due to an unbounded memory leak. Micrometer 1.17.0 Micrometer 1.16.0 - 1.16.6 Micrometer 1.15.0 - 1.15.12 Micrometer 1.14.0 - 1.14.16 Micrometer 1.9.18 and earlier