CVE-2026-59323
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Micrometer Tracing is a tracer-agnostic facade for distributed tracing on the JVM: application and library code opens spans, scopes and baggage against the Micrometer Tracing API, and a bridge module binds that API to a concrete tracer implementation. The micrometer-tracing-bridge-brave module is the bridge to Brave, and it supplies the W3C Trace Context propagators that write and parse the traceparent, tracestate and baggage headers carrying trace state between services. Baggage propagation is active by default in common Boot 3.x setups, so the bridge parses the inbound baggage header on every request that presents one.
A Denial of Service (DoS) vulnerability (CVE-2026-59323) has been identified in the W3C baggage propagator of the Brave bridge, which allows attackers to exhaust heap and CPU resources by sending a request whose baggage header carries a very large number of key and value pairs. The extraction path splits the header on commas and allocates a baggage field for every entry it finds, without enforcing the entry count or header size limits the W3C Baggage specification mandates, so a single inflated header drives unbounded allocation, garbage collection pressure and, in the worst case, an OutOfMemoryError that takes the application down.
Per OWASP: The Denial of Service (DoS) attack is focused on making a resource (site, application, server) unavailable for the purpose it was designed. There are many ways to make a service unavailable for legitimate users by manipulating network packets, programming, logical, or resources handling vulnerabilities, among others. If a service receives a very large number of requests, it may cease to be available to legitimate users. In the same way, a service may stop if a programming vulnerability is exploited, or the way the service handles resources it uses.
This issue affects W3C baggage extraction in the Brave bridge of Micrometer Tracing.
Details
Module Info
- Product: Micrometer Tracing
- Affected packages:
io.micrometer:micrometer-tracing-bridge-brave - Affected versions: <=1.4.13, >=1.5.0 <=1.5.12, >=1.6.0 <=1.6.6, 1.7.0
- GitHub repository: https://github.com/micrometer-metrics/tracing
- Published packages: https://central.sonatype.com/artifact/io.micrometer/micrometer-tracing-bridge-brave
- Package manager: Maven
- Fixed in:
- NES for Micrometer on the Micrometer Tracing nes-1.5.x line
- OSS Micrometer Tracing 1.6.7
Vulnerability Info
This Medium-severity vulnerability is found in the micrometer-tracing-bridge-brave package in the W3C baggage propagator of Micrometer Tracing.
The Brave bridge installs a W3C baggage propagator alongside the traceparent propagator. On extraction, the propagator reads the raw baggage header off the carrier and hands it straight to the parser with no size check:
<R> TraceContextOrSamplingFlags contextWithBaggage(R carrier, TraceContextOrSamplingFlags flags,
Propagation.Getter<R, String> getter) {
String baggageHeader = getter.get(carrier, FIELD);
List<AbstractMap.SimpleEntry<Baggage, String>> pairs = baggageHeader == null || baggageHeader.isEmpty()
? Collections.emptyList() : addBaggageToContext(baggageHeader);
return flags.toBuilder().addExtra(new BraveBaggageFields(pairs)).build();
}The parser then splits the header on commas and walks every resulting entry, registering a baggage field for each key it sees:
List<AbstractMap.SimpleEntry<Baggage, String>> addBaggageToContext(String baggageHeader) {
List<AbstractMap.SimpleEntry<Baggage, String>> pairs = new ArrayList<>();
String[] entries = baggageHeader.split(",");
for (String entry : entries) {
int beginningOfMetadata = entry.indexOf(";");
if (beginningOfMetadata > 0) {
entry = entry.substring(0, beginningOfMetadata);
}
String[] keyAndValue = entry.split("=", 2);
boolean hasValue = keyAndValue.length == 2 && !keyAndValue[1].isEmpty();
if (hasValue) {
try {
String key = keyAndValue[0].trim();
String value = keyAndValue[1].trim();
Baggage baggage = this.braveBaggageManager.createBaggage(key);
pairs.add(new AbstractMap.SimpleEntry<>(baggage, value));
}
catch (Exception e) {
// entry ignored
}
}
}
return pairs;
}Three properties of this loop make it attacker-controlled work. There is no cap on the byte length of the header, so the split alone materializes an array proportional to the attacker's input. There is no cap on the number of entries, so the loop body runs once per comma the attacker supplies. And the key is passed to the baggage manager untouched, with no validation against the RFC 7230 token rules, so every distinct key allocates and retains a new baggage field rather than being rejected. An unauthenticated client that can reach an endpoint where W3C propagation and baggage are enabled only needs to repeat requests carrying a header of many short and unique key and value pairs to drive sustained allocation, garbage collection pressure and eventually an OutOfMemoryError. Because the values are also copied verbatim, the same unvalidated path lets delimiter characters survive a propagation hop into downstream services.
This vulnerability was introduced in 2022 with Micrometer Tracing 1.0.0.
Mitigation
The affected 1.4.x and 1.5.x release lines are End-of-Life and will not receive community updates addressing this issue.
Users of the affected components should apply one of the following mitigations:
- Upgrade Micrometer to a currently supported release containing the fix.
- Reject or truncate inbound
baggageheaders at the edge, and do not acceptbaggageheaders from untrusted callers, as advised by the W3C Trace Context security considerations. - Leverage a commercial support partner like HeroDevs for post-EOL security support.
Credits
- No external finder was credited in the upstream advisory for this issue.