CVE-2026-41708

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
15/06/2026
Last modified:
16/06/2026

Description

In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled.<br /> <br /> Affected versions:<br /> Spring Cloud Sleuth 3.1.0 through 3.1.13.

References to Advisories, Solutions, and Tools