A AegiFlow
HIGHCVSS 7.5EPSS 0.3%

CVE-2026-41708

Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability

Published
2026-06-15
Modified
2026-08-26
EPSS percentile
20%
Aliases
GHSA-26m2-9g2q-v45q
Sources
github-advisory

Summary

In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled. Affected versions: Spring Cloud Sleuth 3.1.0 through 3.1.13.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.springframework.cloud:spring-cloud-sleuth-instrumentation

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.