Description
Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when asynchronous requests fail before receiving a response (e.g. connection resets or timeouts). Tracking state for these requests remains in memory indefinitely, and sustained failures lead to heap exhaustion and OutOfMemoryError crashes.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Migrate to Apache HttpClient 5.6.x's native httpclient5-observation module, or use ObservationExecChainHandler when using HttpClient 5.x with Micrometer 1.12.0+.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 24 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when asynchronous requests fail before receiving a response (e.g. connection resets or timeouts). Tracking state for these requests remains in memory indefinitely, and sustained failures lead to heap exhaustion and OutOfMemoryError crashes. | |
| Title | Micrometer Instrumentation of Apache HttpAsyncClient Denial of Service Vulnerability | |
| Weaknesses | CWE-401 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-08-24T10:10:06.302Z
Reserved: 2026-07-04T18:13:34.323Z
Link: CVE-2026-59295
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses