PT-2026-49304 · Vmware · Spring Cloud Sleuth

CVE-2026-41708

·

Published

2026-06-15

·

Updated

2026-06-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Spring Cloud Sleuth versions 3.1.0 through 3.1.13
Description A denial-of-service (DoS) condition can be triggered when a user provides specially crafted calls. This occurs in applications using the org.springframework.cloud:spring-cloud-sleuth-instrumentation component where Spring TX instrumentation is not disabled.
Recommendations For versions 3.1.0 through 3.1.13, disable Spring TX instrumentation as a mitigation measure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41708
GHSA-26M2-9G2Q-V45Q

Affected Products

Spring Cloud Sleuth