216.73.217.22

CVE-2026-33013

· Published 20/03/2026 05:16 · Modified 20/03/2026 13:37

Labels: CVE-2026-33013 2026-03-20CVE-2026-33013CWE-835[email protected]

Essential information

Published
20/03/2026 05:16
Modified
20/03/2026 13:37
Author
Creator
CVSS
8.2 HIGH (v3) 8.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., authors[1].name followed by authors[0].name). This issue has been fixed in versions 4.10.16 and 3.10.5.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
micronaut / micronaut framework cpe:2.3:a:micronaut:micronaut_framework:<4.10.16:*:*:*:*:*:*:*
micronaut / micronaut framework cpe:2.3:a:micronaut:micronaut_framework:<3.10.5:*:*:*:*:*:*:*

References