VYPR

security-advisories

by Spring Projects

CVEs (1)

  • CVE-2026-59295MedAug 24, 2026
    risk 0.38cvss 5.9epss

    Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when asynchronous requests fail before receiving a response (e.g. connection resets or timeouts). Tracking state for these requests remains in memory…