CVE-2026-41708

In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled. Affected versions: Spring Cloud Sleuth 3.1.0 through 3.1.13.
References
Link Resource
https://spring.io/security/cve-2026-41708 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:broadcom:spring_cloud_sleuth:*:*:*:*:*:*:*:*

History

17 Jun 2026, 16:28

Type Values Removed Values Added
References () https://spring.io/security/cve-2026-41708 - () https://spring.io/security/cve-2026-41708 - Vendor Advisory
First Time Broadcom
Broadcom spring Cloud Sleuth
CPE cpe:2.3:a:broadcom:spring_cloud_sleuth:*:*:*:*:*:*:*:*

15 Jun 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-15 20:16

Updated : 2026-06-17 16:28


NVD link : CVE-2026-41708

Mitre link : CVE-2026-41708

CVE.ORG link : CVE-2026-41708


JSON object : View

Products Affected

broadcom

  • spring_cloud_sleuth
CWE
CWE-400

Uncontrolled Resource Consumption