Micronaut
Objectcomputing · 6 CVEs
CVE-2026-33013
HIGH
Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices
Mar 20, 2026
CVE-2026-33012
HIGH
Micronaut Framework vulnerable to a Denial of Service in HTML error response caching
Mar 20, 2026
CVE-2024-23639
HIGH
micronaut-core management endpoints vulnerable to drive-by localhost attack
Feb 9, 2024
CVE-2022-21700
MEDIUM
Memory leak in micronaut-core
Jan 18, 2022
CVE-2021-32769
HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in micronaut-core
Jul 16, 2021
CVE-2020-7611
CRITICAL
All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerabl…
Mar 30, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-33013 | Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices | HIGH | 0.78% | Mar 20, 2026 |
| CVE-2026-33012 | Micronaut Framework vulnerable to a Denial of Service in HTML error response caching | HIGH | 0.75% | Mar 20, 2026 |
| CVE-2024-23639 | micronaut-core management endpoints vulnerable to drive-by localhost attack | HIGH | 0.26% | Feb 9, 2024 |
| CVE-2022-21700 | Memory leak in micronaut-core | MEDIUM | 1.15% | Jan 18, 2022 |
| CVE-2021-32769 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in micronaut-core | HIGH | 1.73% | Jul 16, 2021 |
| CVE-2020-7611 | All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due t… | CRITICAL | 1.81% | Mar 30, 2020 |
Showing 1 to 6 of 6 CVEs