CVE-2026-59323
CVE-2026-59323: 1 tracked advisory record across VMware. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
VMware
1 advisory- Advisory severityMedium5.3
Medium [CVE-2026-59323] Spring Boot: application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of s…
CVE-2026-59323Source published Source updated
An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers. Specifically, an application is vulnerable when all the following are true: - W3C propagation is active (either configured manually or active by default, such as in Spring Boot 3.x+). - Baggage propagation is enabled (which is the default in Spring Boot 3.x+) and a baggage manager (such as BraveBaggageManager) is configured to handle baggage fields. - The application processes requests or messages from untrusted sources with baggage headers which it normally should not, see:. - Network components including the (HTTP) server that receives the request do not limit the header size or the…
- Affected products in this advisory
- Spring
- Source-reported affected versions
- Spring 1.7.0 - 1.7.0 before 1.7.0.1
- Spring 1.7.0 - 1.7.0 before 1.7.1
- Spring 1.6.0 - 1.6.6 before 1.6.6.1
- Spring 1.6.0 - 1.6.6 before 1.6.7
2 more entries in the full advisory.
- Source-reported fixed versions
- 1.7.0.1
- 1.7.1
- 1.6.6.1
- 1.6.7
2 more entries in the full advisory.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future VMware CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.