CVE-2026-41708
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
15/06/2026
Last modified:
16/06/2026
Description
In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled.<br />
<br />
Affected versions:<br />
Spring Cloud Sleuth 3.1.0 through 3.1.13.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



