Description

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through 4.10.16 used an unbounded ConcurrentHashMap cache with no eviction policy in its DefaultHtmlErrorResponseBodyProvider. If the application throws an exception whose message may be influenced by an attacker, (for example, including request query value parameters) it could be used by remote attackers to cause an unbounded heap growth and OutOfMemoryError, leading to DoS. This issue has been fixed in version 4.10.7.

INFO

Published Date :

2026-03-20T04:43:07.809Z

Last Modified :

2026-03-20T16:02:36.357Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-33012 vulnerability.

Vendors Products
Micronaut-projects
  • Micronaut-core
Objectcomputing
  • Micronaut

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact