Medium [CVE-2026-59296] Line-protocol and log injection via unsanitized input allows metric and log spoofing
This medium-severity Red Hat Linux advisory covers CVE-2026-59296 affecting Red Hat build of Apache Camel 4.18.4 for Spring Boot 3.5.16, Red Hat Data Grid 8.6.3, Red Hat OpenShift Dev Spaces 3.30.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform.
When such unsafe instrumentation is used, the application becomes vulnerable to injection and spoofing attacks because micrometer-registry-statsd and micrometer-core do not sanitize newline characters (\n, \r) by default prior to this fix. * For the StatsD registry in micrometer-registry-statsd (when using the Datadog or Etsy flavor), because the StatsD protocol is newline-delimited, this allows for line-protocol injection (cross-metric spoofing). * For LoggingMeterRegistry in micrometer-core, because metric output is printed line-by-line to log files, this allows for both metric spoofing (if downstream log-metrics scrapers or parsers ingest the log lines as separate metrics) and general log spoofing.
Specifically, an application is vulnerable when all the following are true: * The application uses a vulnerable version of io.micrometer:micrometer-registry-statsd or io.micrometer:micrometer-core. * The application uses the Datadog or Etsy flavor of the StatsD registry, or uses LoggingMeterRegistry. * The application instruments meters using user-controlled, unvalidated input for metric names, tag keys, or tag values.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 9 days ago·verify at source
- micrometer-core
- devspaces/openvsx-rhel9:1787759145
- devspaces/pluginregistry-rhel9:1787759723
- RHSA-2026:71675
- RHSA-2026:69296
- RHSA-2026:62260
Official advisory · high-confidence parse· fetched 9 days ago·verify at source
Mitigation
Upgrade to a fixed release: micrometer-core, devspaces/openvsx-rhel9:1787759145, devspaces/pluginregistry-rhel9:1787759723, RHSA-2026:71675, RHSA-2026:69296, RHSA-2026:62260. That is the remediation for this advisory.
The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.
Official advisory · high-confidence parse· fetched 9 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.