cvedb.io
CVE-2026-41708
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2026-06-15T20:16:27.940 · Last modified 2026-06-17T16:28:17.350

Summary

In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled. Affected versions: Spring Cloud Sleuth 3.1.0 through 3.1.13.

Affected products

broadcom — spring_cloud_sleuth

Does this affect you?

Add your gear to cvedb and we'll alert you only when broadcom ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.