CVE-2026-33012General(objectcomputing / micronaut)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through 4.10.16 used an unbounded ConcurrentHashMap cache with no eviction policy in its DefaultHtmlErrorResponseBodyProvider. If the application throws an exception whose message may be influenced by an attacker, (for example, including request query value parameters) it could be used by remote attackers to cause an unbounded heap growth and OutOfMemoryError, leading to DoS. This issue has been fixed in version 4.10.7.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • micronaut

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
micronaut

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-22: 1PoC Mentioned / Linked · 2026-03-22: 1Technical Details · 2026-03-22: 103-2003-22
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-201
General1
2026-03-221
Disclosure1
Full discourse2 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    Micronaut Framework has a Denial of Service vulnerability (CVE-2026-33012) related to HTML error response caching. Review error handling and monitor for updates. #Micronaut #DoS #AppSec https://www.pulsepatch.io/posts/cve-2026-33012-micronaut-framework-denial-of-service

    Post summary

    The tweet announces a new DoS vulnerability (CVE-2026-33012) in Micronaut Framework, advising checking error handling and staying alert for patches, but it does not provide PoC details, exploit code, or evidence of active exploitation.

    0000033
    2 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33012 Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through 4.10.16 used an … https://www.cve.org/CVERecord?id=CVE-2026-33012

    Post summary

    The post merely references CVE-2026-33012 for certain Micronaut Framework versions without offering any exploitation, patch, or technical details.

    0000075
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appobjectcomputingmicronaut---

Explore more