PT-2026-58938 · Maven · Io.Micronaut:Micronaut-Http-Client

Published

2026-07-09

·

Updated

2026-07-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The Netty-based Micronaut HTTP Client does not impose a limit on HTTP redirections, potentially allowing an infinite redirect loop that could lead to a denial-of-service attack.

Patches

The following versions are patched:
  • For Micronaut 5, versions equal or greater than 5.0.1 >=
  • For Micronaut 4, versions equal or greater than 4.10.24 >=
  • For Micronaut 3, versions equal or greater than 3.10.7 >=

Workarounds

No

Resources

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-387M-935M-C4VW

Affected Products

Io.Micronaut:Micronaut-Http-Client