Medium severity5.9NVD Advisory· Published Aug 24, 2026
CVE-2026-59295
CVE-2026-59295
Description
Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when asynchronous requests fail before receiving a response (e.g. connection resets or timeouts). Tracking state for these requests remains in memory indefinitely, and sustained failures lead to heap exhaustion and OutOfMemoryError crashes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 4.x or 5.x
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.